CVE-2026-50575: BetterDesk has a replay behavior vulnerability when devices are deleted
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BetterDeskto a version that resolves this vulnerability.Fixed in 3.0.0-alpha
Event History
Frequently Asked Questions
Which BetterDesk versions are affected and which version contains a fix?
Deployments running BetterDesk versions through 2.3.0 are affected. The available data identifies version 3.0.0-alpha as containing a patch.
What does an attacker need to exploit this issue?
An unauthenticated client can replay or spoof the identity of a deleted device. This can bypass registration controls without requiring user interaction.
What can be done if patching cannot be performed immediately?
No known workaround is available. Updating to a version that contains the patch is the only remediation stated in the available data.