Junglewise Threat Intelligence

CVE-2026-44040: UltraVNC weak PRNG in VNC authentication challenge

CVE-2026-44040 · Severity: medium · CVSS 4.8 · Published 2026-07-01

Technologies: UltraVNC. Vendors: UltraVNC.

Executive brief

UltraVNC, a popular remote desktop tool used for technical support and remote server management, contains a security weakness in how it handles login requests. The software uses a predictable method to generate the security 'challenges' used during authentication, which could allow an attacker to bypass login protections. If exploited, an unauthorized user could potentially gain remote control of the computer, leading to data theft or unauthorized system changes.

Technical details

UltraVNC (up to version 1.8.2.2) utilizes a weak PRNG in its authentication handshake. Specifically, in rfb/vncauth.c, the vncRandomBytes() function seeds the standard libc rand() function using a combination of the current time, process ID, and a previous rand() call. This results in a seed space of approximately 31 bits, which is composed entirely of values observable or predictable by a network attacker. By observing an authentication exchange, an attacker can enumerate the seed space within seconds to predict the challenge bytes. This enables the forgery of authentication responses or facilitates efficient offline brute-force attacks against the VNC password. While Windows builds may use a more secure CryptGenRandom path, the reachability of the vulnerable code in official binaries is currently under investigation.

Affected products

  • uvnc UltraVNC through 1.8.2.2

Timeline

  • 2026-07-01: advisory: CVE-2026-44040 published by NVD

References

Related threats