๐Ÿ” CVE Alert

CVE-2026-50575

HIGH 7.7

BetterDesk has a replay behavior vulnerability when devices are deleted

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.

CWE CWE-294 CWE-345 CWE-672
Vendor unitronix
Product betterdesk
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for unitronix betterdesk

Be the first to know when new high vulnerabilities affecting unitronix betterdesk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

UNITRONIX / BetterDesk
< 3.0.0-alpha

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/UNITRONIX/BetterDesk/security/advisories/GHSA-3v82-3gf8-fxx8 github.com: https://github.com/UNITRONIX/BetterDesk/commit/f3b4df28240694b174158335e4c0c51c8dfbe4ab