Junglewise Threat Intelligence

CVE-2026-15682: AnyDesk link following denial of service in Send Support Information

CVE-2026-15682 · Severity: medium · CVSS 4.7 · Published 2026-07-13

Technologies: AnyDesk. Vendors: AnyDesk.

Executive brief

A vulnerability in AnyDesk, a popular remote desktop application, could allow a local user to crash the software or disrupt system operations. By exploiting a flaw in how the application handles support information requests, an attacker who already has limited access to a computer can create unauthorized files that interfere with the system's stability. This could lead to a denial-of-service, preventing legitimate users from accessing the remote desktop service or other system functions.

Technical details

A link following vulnerability (CWE-59) exists within the 'Send Support Information' feature of AnyDesk version 9.0.4. The flaw stems from improper validation of file paths when the service handles support data, allowing a local attacker with low privileges to create directory junctions. By redirecting file operations via these junctions, the attacker can force the high-privileged AnyDesk service to create arbitrary files on the filesystem. This capability can be leveraged to cause a denial-of-service (DoS) condition. The attack requires local code execution and faces high architectural complexity (AC:H) to successfully time the junction creation.

Affected products

  • AnyDesk AnyDesk 9.0.4

Timeline

  • 2025-03-30: disclosed: Vulnerability reported to vendor
  • 2026-07-08: advisory: Coordinated public release of advisory by Zero Day Initiative
  • 2026-07-13: other: NVD publication date

References

Related threats