VYPR
Medium severity5.5NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2026-12162

CVE-2026-12162

Description

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:windows:*:*+ 1 more
    • cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:windows:*:*range: <2026.2.9.0
    • (no CPE)range: 2026.2.8

Patches

Vulnerability mechanics

References

1

News mentions

1