Improper host validation in the social login autofill feature in
Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to
disclose stored social login credentials via a crafted web entry
pointing to a provider lookalike domain.
References
| Link | Resource |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0018/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-06-16 01:16
Updated : 2026-06-17 10:14
NVD link : CVE-2026-12162
Mitre link : CVE-2026-12162
CVE.ORG link : CVE-2026-12162
JSON object : View
Products Affected
devolutions
- remote_desktop_manager
CWE
CWE-297
Improper Validation of Certificate with Host Mismatch
