CVE-2026-58056
HIGH
7.6
CVSS 3.1
Description
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.
Metadata
Severity & Metrics
7.6
HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| RustDesk | RustDesk | — | 0 ≤ ff226f6d8013dee2de5a6553abaf67bf32b3e875 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-863 | cna | Incorrect Authorization |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 7.6 | HIGH | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
| 7.2 | HIGH | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
References (2)
- Proof of Concept https://github.com/bikini/exploitarium/tree/main/rustdesk-session-permission-pocs
- VulnCheck Advisory: RustDesk - FileTransfer Session Authorization Scope Bypass https://www.vulncheck.com/advisories/rustdesk-filetransfer-session-authorization-scope-bypass