CVE-2026-2590: Input Validation
Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by creating or editing certain connection types while password saving is disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2590?
CVE-2026-2590 has been classified as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2026-2590?
To mitigate CVE-2026-2590, update Devolutions Remote Desktop Manager to version 2025.3.31 or later.
What is the impact of CVE-2026-2590?
CVE-2026-2590 allows authenticated users to save credentials in vault entries, risking unauthorized access to sensitive information.
Who is affected by CVE-2026-2590?
CVE-2026-2590 affects all users of Devolutions Remote Desktop Manager version 2025.3.30 and earlier.
Is there a workaround for CVE-2026-2590?
As a temporary workaround for CVE-2026-2590, users can manually disable password saving in their configuration settings until an update is applied.