CVE-2026-30793: RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation
Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with program files flutter/lib/common.Dart, src/flutterffi.Rs and program routines URI handler for rustdesk://password/, bind.MainSetPermanentPassword().
This issue affects RustDesk Client: through 1.4.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30793?
CVE-2026-30793 is considered a high severity vulnerability due to its potential for unauthorized access and control over the RustDesk Client.
How do I fix CVE-2026-30793?
To fix CVE-2026-30793, users should upgrade to RustDesk Client version 1.4.6 or later, where the vulnerability has been addressed.
What platforms are affected by CVE-2026-30793?
CVE-2026-30793 affects RustDesk Client on Windows, MacOS, Linux, iOS, and Android.
What type of vulnerability is CVE-2026-30793?
CVE-2026-30793 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability that can set a permanent password without user confirmation.
Is user interaction required to exploit CVE-2026-30793?
Exploiting CVE-2026-30793 does not require user interaction, making it particularly dangerous.