Junglewise Threat Intelligence

CVE-2026-30789: RustDesk Client authentication bypass via session replay and weak hashing

CVE-2026-30789 · Severity: critical · CVSS 9.8 · Published 2026-03-05

Technologies: Rustdesk, Apple macOS, Microsoft Windows, Google Android, RustDesk Client, Linux Kernel, Apple Iphone Os. Vendors: Rustdesk, Apple, Microsoft, Google, Linux.

Executive brief

RustDesk is a remote desktop application used to access and control computers over a network. A security flaw in the client software allows attackers to bypass authentication by capturing and replaying login sessions or by cracking weak password hashes. This could allow an unauthorized person to gain full remote control over a user's device, potentially leading to data theft or system compromise.

Technical details

An authentication bypass vulnerability exists in RustDesk Client through version 1.4.5 due to improper session management and weak cryptographic practices. The software is susceptible to capture-replay attacks where an attacker can reuse intercepted Session IDs to gain unauthorized access. Additionally, the 'hash_password()' routine and login proof construction in 'src/client.rs' utilize password hashing with insufficient computational effort (CWE-916), making them vulnerable to offline brute-force attacks. These flaws allow a network-based attacker to bypass peer authentication and gain remote control of the affected system without valid credentials. Version 1.4.8 appears to address several related security issues, though users are advised to update to the latest available release.

Affected products

  • RustDesk RustDesk Client through 1.4.5

Timeline

  • 2026-03-05: disclosed: Initial disclosure by VULSec Labs
  • 2026-03-05: advisory: CVE-2026-30789 published
  • 2026-06-21: patched: Version 1.4.8 released (addressing related vulnerabilities)

References

Related threats