CVE-2026-57850: RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An authenticated remote peer can exploit this missing scope check to act outside its granted scope, injecting out-of-scope control messages to observe and control the host beyond the permissions it was given.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57850?
CVE-2026-57850 has a high severity score of 8.7.
How do I fix CVE-2026-57850?
To fix CVE-2026-57850, update RustDesk to version 1.4.9 or later.
What vulnerability does CVE-2026-57850 present?
CVE-2026-57850 allows out-of-scope control message injection due to missing session scope enforcement.
What impact does CVE-2026-57850 have on affected systems?
CVE-2026-57850 allows limited session types to send unauthorized control messages, which can compromise system integrity.
Which versions of RustDesk are affected by CVE-2026-57850?
RustDesk versions before 1.4.9 are affected by CVE-2026-57850.