Junglewise Threat Intelligence

CVE-2026-15681: AnyDesk link following denial of service in screen recording

CVE-2026-15681 · Severity: medium · CVSS 4.7 · Published 2026-07-13

Technologies: AnyDesk. Vendors: AnyDesk.

Executive brief

A vulnerability in AnyDesk, a popular remote desktop application, allows a local user with limited permissions to disrupt the system's stability. By manipulating how the software saves screen recordings, an attacker can force the creation of files in restricted locations, potentially leading to a system crash or service outage. This could impact business operations by rendering the affected computer unavailable for remote support or standard use.

Technical details

This vulnerability is classified as an improper link resolution (CWE-59) flaw within the screen recording component of AnyDesk. The root cause is the application's failure to properly validate file paths when handling recording files, allowing a local attacker to create directory junctions. By exploiting this, a low-privileged user can trick the high-privileged AnyDesk service into creating arbitrary files in sensitive system locations. This capability can be leveraged to trigger a denial-of-service (DoS) condition. The attack requires local code execution and carries a high complexity due to the specific timing or environmental conditions needed to redirect the file operations.

Affected products

  • AnyDesk AnyDesk 9.0.4

Timeline

  • 2025-03-25: disclosed: Vulnerability reported to vendor
  • 2026-07-13: advisory: Coordinated public release of advisory

References

Related threats