Devolutions Remote Desktop Manager
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:*:*
- <= 2025.3.30
A vulnerability exists in Devolutions Remote Desktop Manager in versions through 2025.3.30 that improperly enforces the setting to disable password saving in vaults. This flaw allows authenticated users to save credentials in vault entries, potentially exposing sensitive information to other users. The issue arises when certain connection types are created or edited while password saving is disabled.
Exploitation of this vulnerability could lead to unauthorized credential storage in vaults, allowing sensitive information to be shared with other users.
Users are advised to upgrade to Devolutions Remote Desktop Manager version 2026.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.