Unrated severityNVD Advisory· Published Jun 28, 2026· Updated Jul 18, 2026
RustDesk - FileTransfer Session Authorization Scope Bypass
CVE-2026-58056
Description
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/bikini/exploitarium/tree/main/rustdesk-session-permission-pocsmitreexploitthird-party-advisory
- www.vulncheck.com/advisories/rustdesk-filetransfer-session-authorization-scope-bypassmitrethird-party-advisory
News mentions
0No linked articles in our index yet.