CVE-2026-3598: RustDesk Server Generates Config Strings Using Reversible Encoding (Base64 + Reverse) Instead of Encryption

Published Mar 5, 2026
·
Updated

Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Config string generation, web console export modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program routines Config export/generation routines.

This issue affects RustDesk Server Pro: through 1.7.5.

Affected Software

5 affected components
RustDesk RustDesk Server Pro<=1.7.5
All of the following
RustDesk RustDesk Server<=1.7.5
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows

Remediation

Information

Implement AES-256-GCM AEAD or equivalent authenticated encryption

Event History

Mar 5, 2026
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Sep 22, 58202
Event
via FIRST·10:41 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-3598?

CVE-2026-3598 has been classified with a medium severity rating due to its use of reversible encoding instead of strong encryption.

2

How do I fix CVE-2026-3598?

To mitigate CVE-2026-3598, update to a newer version of RustDesk Server Pro that uses secure encryption methods instead of reversible encoding.

3

Which versions of RustDesk Server Pro are affected by CVE-2026-3598?

CVE-2026-3598 affects versions of RustDesk Server Pro up to and including 1.7.5.

4

What types of systems are impacted by CVE-2026-3598?

CVE-2026-3598 impacts RustDesk Server Pro installations on Windows, MacOS, and Linux.

5

Is CVE-2026-3598 related to the security of configuration strings?

Yes, CVE-2026-3598 specifically relates to the insecure generation of configuration strings using reversible encoding, which could expose sensitive information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203