Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.2
CVE-2026-58056: RustDesk: Unauthorized input injection through file transfer
CVE-2026-58056
CVE-2026-58056
Summary
RustDesk allows unauthorized access to keyboard, mouse, and screen capture functions when a file transfer is initiated. This means a user with limited permissions can potentially gain control of the computer and access sensitive information. To mitigate this risk, update to the latest version of RustDesk.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| rustdesk | rustdesk | <= 1.4.8 |
Original title
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only...
Original description
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.
nvd CVSS3.1
7.6
nvd CVSS4.0
7.2
Vulnerability type
CWE-863
Incorrect Authorization
Published: 28 Jun 2026 · Updated: 18 Jul 2026 · First seen: 28 Jun 2026