Data Authenticity Vulnerability in IronVNC Client by Devolutions
CVE-2026-78417
Currently unrated
What is CVE-2026-78417?
The IronVNC client in Devolutions Remote Desktop Manager exhibits a vulnerability that allows an on-path attacker to intercept and potentially modify VNC session data. This occurs due to the automatic acceptance of the server's RSA key during the RSA-AES authentication process, which compromises the integrity of communication. Affected versions include Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, as well as 2026.1.24.0 and earlier. Users should be aware of the risk associated with this deficiency and take appropriate measures to secure their VNC sessions.
Affected Version(s)
Remote Desktop Manager 0 < 2026.2.18
Remote Desktop Manager 0 < 2026.1.25
