CVE-2026-30796
RustDesk Server Pro API Requires Address Book Password in Plaintext for Sync Protocol
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Cleartext Transmission of Sensitive Information vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Address book sync API modules) allows Sniffing Attacks. This vulnerability is associated with program files Closed source โ API endpoint handling heartbeat sync and program routines Heartbeat API handler (accepts preset-address-book-password in plaintext). This issue affects RustDesk Server Pro: through 1.7.5.
| CWE | CWE-319 |
| Vendor | rustdesk-server-pro |
| Product | rustdesk server pro |
| Published | Mar 5, 2026 |
| Last Updated | Mar 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for rustdesk-server-pro rustdesk server pro
Be the first to know when new unknown vulnerabilities affecting rustdesk-server-pro rustdesk server pro are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
rustdesk-server-pro / RustDesk Server Pro
0 โค 1.7.5
References
Credits
Erez Kalman ๐ Erez Kalman