Description
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Published: 2026-08-24
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title On-Path Attacker Can Tamper with VNC Sessions via Unverified RSA Key Acceptance

Mon, 24 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions remote Desktop Manager
Vendors & Products Devolutions
Devolutions remote Desktop Manager

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Weaknesses CWE-345
References

Subscriptions

Devolutions Remote Desktop Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-08-24T18:26:25.739Z

Reserved: 2026-08-24T15:10:53.447Z

Link: CVE-2026-78417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T19:17:04.420

Modified: 2026-08-24T19:17:04.420

Link: CVE-2026-78417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:30:07Z

Weaknesses