๐Ÿ” CVE Alert

CVE-2026-12162

MEDIUM 5.5
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

Vendor devolutions
Product remote desktop manager
Published Jun 15, 2026
Last Updated Jun 16, 2026
Stay Ahead of the Next One

Get instant alerts for devolutions remote desktop manager

Be the first to know when new medium vulnerabilities affecting devolutions remote desktop manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Devolutions / Remote Desktop Manager
2026.2.0 โ‰ค 2026.2.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
devolutions.net: https://devolutions.net/security/advisories/DEVO-2026-0018/