Description
Improper
enforcement of the Disable password saving in vaults setting in the
connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries,
potentially exposing sensitive information to other users, by creating
or editing certain connection types while password saving is disabled.
Published: 2026-03-03
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Devolutions Remote Desktop Manager versions 2025.3.30 and earlier do not correctly enforce the “Disable password saving in vaults” option when users create or edit certain connection types. Because the application does not validate this setting, an authenticated user can store passwords in vault entries even when password saving is turned off. The vulnerability arises from improper input validation (CWE‑20) and insecure credential storage enforcement (CWE‑295), leading to potential disclosure of sensitive credentials to other users or processes that can access the vault.

Affected Systems

The problem affects copies of Devolutions Remote Desktop Manager 2025.3.30 and older running on Windows. Any user with authenticated access to the application can create or edit connection entries that contain passwords, allowing them to preserve those credentials in the vault regardless of the user‑selected setting.

Risk and Exploitability

The CVSS score of 9.8 indicates a high‑severity flaw. Exploitation requires legitimate authentication, but the attacker can then persist credentials that remain accessible to other users who can read the vault. EPSS indicates an extremely low probability of real‑world exploitation at the moment, and the flaw is not listed in CISA’s KEV catalog. The attack vector involves a legitimate user interface action within the application, so a user with appropriate role privileges can carry out the exploitation without advanced technical skills.

Generated by OpenCVE AI on May 10, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade to a version newer than 2025.3.30 that corrects the password‑saving enforcement logic
  • Limit user permissions so that only trusted personnel can create or edit connection entries that might store passwords
  • Perform regular audits of vault contents to detect and remove inadvertently stored credentials, ensuring that the disable password‑saving option is truly respected

Generated by OpenCVE AI on May 10, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 10 May 2026 15:45:00 +0000

Type Values Removed Values Added
Title Credential Persistence via Improper Password Saving Enforcement

Sun, 10 May 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Fri, 17 Apr 2026 13:45:00 +0000

Type Values Removed Values Added
Title Credential Persistence via Improper Password Saving Enforcement

Thu, 05 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CPEs cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:windows:*:*

Wed, 04 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions remote Desktop Manager
Vendors & Products Devolutions
Devolutions remote Desktop Manager

Tue, 03 Mar 2026 21:45:00 +0000

Type Values Removed Values Added
Description Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by creating or editing certain connection types while password saving is disabled.
References

Subscriptions

Devolutions Remote Desktop Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-05-10T12:55:59.865Z

Reserved: 2026-02-16T15:57:08.878Z

Link: CVE-2026-2590

cve-icon Vulnrichment

Updated: 2026-03-04T14:44:03.284Z

cve-icon NVD

Status : Modified

Published: 2026-03-03T22:16:29.157

Modified: 2026-05-10T13:16:35.887

Link: CVE-2026-2590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-10T15:30:14Z

Weaknesses