VYPR

Rustdesk Server

by Rustdesk

CVEs (4)

  • CVE-2026-57850HigJul 10, 2026
    risk 0.54cvss 8.3epss 0.00

    RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An…

  • CVE-2026-30796HigMar 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks. The client…

  • CVE-2026-3598HigMar 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Config string generation, web console export modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated…

  • CVE-2026-58056HigJun 28, 2026
    risk 0.00cvss 7.6epss 0.00

    RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach…