Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.

Project Subscriptions

Vendors Products
Devolutions Subscribe
Remote Desktop Manager Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title On-Path Attacker Can Tamper with VNC Sessions via Unverified RSA Key Acceptance

Mon, 24 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions remote Desktop Manager
Vendors & Products Devolutions
Devolutions remote Desktop Manager

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Weaknesses CWE-345
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-08-24T18:26:25.739Z

Reserved: 2026-08-24T15:10:53.447Z

Link: CVE-2026-78417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T19:17:04.420

Modified: 2026-08-24T19:17:04.420

Link: CVE-2026-78417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:30:07Z

Weaknesses