CVE-2026-78417

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-24 19:17

Updated : 2026-08-28 20:19


NVD link : CVE-2026-78417

Mitre link : CVE-2026-78417

CVE.ORG link : CVE-2026-78417


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity