Improper host validation in the social login autofill feature in
Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to
disclose stored social login credentials via a crafted web entry
pointing to a provider lookalike domain.
References
| Link | Resource |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0018/ | Vendor Advisory |
Configurations
History
16 Jun 2026, 20:33
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:windows:*:* | |
| References | () https://devolutions.net/security/advisories/DEVO-2026-0018/ - Vendor Advisory | |
| First Time |
Devolutions
Devolutions remote Desktop Manager |
16 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| CWE | CWE-297 |
16 Jun 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-16 01:16
Updated : 2026-06-17 10:14
NVD link : CVE-2026-12162
Mitre link : CVE-2026-12162
CVE.ORG link : CVE-2026-12162
JSON object : View
Products Affected
devolutions
- remote_desktop_manager
CWE
CWE-297
Improper Validation of Certificate with Host Mismatch
