Junglewise Threat Intelligence

CVE-2026-30784: RustDesk Server authentication bypass in hbbs and hbbr modules

CVE-2026-30784 · Severity: info · CVSS 9.8 · Published 2026-03-05

Technologies: RustDesk Server Pro. Vendors: Rustdesk.

Executive brief

RustDesk Server, a self-hosted remote desktop solution, contains a critical security flaw in its rendezvous and relay modules. This vulnerability allows unauthorized individuals to bypass authentication and abuse administrative privileges. An attacker could potentially intercept remote desktop sessions or gain unauthorized access to the server's core functions, compromising the privacy and security of all remote connections managed by the server.

Technical details

A critical vulnerability (originally tracked as CVE-2026-30784 before being withdrawn) exists in RustDesk Server (OSS and Pro) due to missing authorization and authentication for critical functions. The flaw is located in the Rendezvous server (hbbs) and relay server (hbbr) modules, specifically affecting program routines such as handle_punch_hole_request(), RegisterPeer handler, and relay forwarding within src/rendezvous_server.rs and src/relay_server.rs. A remote, unauthenticated attacker can exploit these weaknesses to achieve privilege abuse and total technical impact over the server's operations. While the CVE was withdrawn by the CNA, the technical details indicate a significant risk to versions up to 1.7.5 (Pro) and 1.1.15 (OSS).

Affected products

  • RustDesk RustDesk Server Pro up to and including 1.7.5
  • RustDesk RustDesk Server OSS up to and including 1.1.15

Timeline

  • 2026-03-05: disclosed: Initial publication date
  • 2026-06-22: other: CVE was withdrawn/rejected by the CNA

Related threats