CVE-2026-15682: (0Day) AnyDesk Support Information Link Following Denial-of-Service Vulnerability
AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the (DoS / arbitrary file creation via junction) issue described for AnyDesk by disabling or not using the AnyDesk "Send Support Information" feature on affected installations, since the flaw exists within that feature. ZDI-CAN-26645.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15682?
The severity of CVE-2026-15682 is rated as medium with a score of 4.7.
How do I fix CVE-2026-15682?
To fix CVE-2026-15682, ensure you update your AnyDesk installation to the latest version provided by the vendor.
What type of attack does CVE-2026-15682 enable?
CVE-2026-15682 enables local attackers to create a denial-of-service condition on affected AnyDesk installations.
What are the conditions required for exploiting CVE-2026-15682?
An attacker must have the ability to execute low-privileged code on the target system to exploit CVE-2026-15682.
Which software is affected by CVE-2026-15682?
CVE-2026-15682 affects AnyDesk versions that have not been updated to mitigate the vulnerability.