CVE-2026-58056
RustDesk - FileTransfer Session Authorization Scope Bypass
CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.
| CWE | CWE-863 |
| Vendor | rustdesk |
| Product | rustdesk |
| Published | Jun 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for rustdesk rustdesk
Be the first to know when new high vulnerabilities affecting rustdesk rustdesk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low
Affected Versions
RustDesk / RustDesk
0 โค ff226f6d8013dee2de5a6553abaf67bf32b3e875
References
Credits
ashdfrkl