CVE-2026-12162EPSS p1.7%
CVE-2026-12162CVE-2026-12162
devolutions / remote_desktop_manager
Description
Improper host validation in the social login autofill feature in
Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to
disclose stored social login credentials via a crafted web entry
pointing to a provider lookalike domain.
Scoring
| CVSS | 5.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
| EPSS | 0.11% probability of exploitation · percentile 1.7% · 2026-06-18T12:00:27Z |
| Last modified | 2026-06-16 |