CVE-2026-12162: Medium severity Devolutions Remote Desktop Manager vulnerability
Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the social login autofill feature or automatic credential autofill in Remote Desktop Manager until a vendor patch is available.
Devolutions Remote Desktop Manager social login autofill = disabled - Compensating control
Restrict addition and use of web entries to trusted administrators and block or filter access to provider lookalike domains via DNS, firewall, or web proxy to prevent crafted web entries from reaching users.
- Operational
Review Remote Desktop Manager for any untrusted or suspicious web entries and remove or quarantine any entries that point to lookalike domains.
- Operational
Rotate all social login credentials stored in Remote Desktop Manager that may have been exposed once mitigations are in place.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12162?
CVE-2026-12162 has a risk score of 60, indicating a medium severity issue.
How do I fix CVE-2026-12162?
To fix CVE-2026-12162, update to Devolutions Remote Desktop Manager version 2026.2.9 or later.
What does CVE-2026-12162 exploit?
CVE-2026-12162 exploits improper host validation in the social login autofill feature.
What are the potential impacts of CVE-2026-12162?
CVE-2026-12162 can allow an attacker to disclose stored social login credentials.
Which software is affected by CVE-2026-12162?
CVE-2026-12162 affects Devolutions Remote Desktop Manager version 2026.2.8.