Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-57850: RustDesk before 1.4.9 Allows Unauthorized Access

CVE-2026-57850 CVE-2026-57850
Summary

A security issue in RustDesk before version 1.4.9 allows an authenticated user to access features they shouldn't be able to, like controlling the host's camera or transferring files, even if they're only supposed to have limited permissions. This could potentially allow unauthorized access to sensitive information or actions. To fix this, update RustDesk to version 1.4.9 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
rustdesk rustdesk < 1.4.9
Original title
RustDesk before 1.4.9 Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
Original description
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An authenticated remote peer can exploit this missing scope check to act outside its granted scope, injecting out-of-scope control messages to observe and control the host beyond the permissions it was given.
nvd CVSS3.1 8.3
nvd CVSS4.0 8.7
Vulnerability type
CWE-862 Missing Authorization
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 10 Jul 2026