CVE-2026-57850
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
10/07/2026
Last modified:
20/07/2026
Description
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An authenticated remote peer can exploit this missing scope check to act outside its granted scope, injecting out-of-scope control messages to observe and control the host beyond the permissions it was given.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.30
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/rustdesk/rustdesk
- https://github.com/rustdesk/rustdesk/commit/493b14ba78abc3dfb33f109c7f93c1c95a1dabc4
- https://github.com/rustdesk/rustdesk/pull/15469
- https://github.com/rustdesk/rustdesk/releases/tag/1.4.9
- https://www.vulncheck.com/advisories/rustdesk-missing-session-scope-enforcement-allows-out-of-scope-control-message-injection



