Junglewise Threat Intelligence

CVE-2026-55977: EShare ESharePro rate-limiting bypass in screen-sharing

CVE-2026-55977 · Severity: low · CVSS 3.3 · Published 2026-07-28

Executive brief

EShare is a wireless screen-sharing and collaboration application used to cast content from personal devices to smart TVs. A security flaw allows an attacker on the same local network to bypass security protections and guess the screen-sharing access code. If successful, an unauthorized user could take control of the display to show harmful or inappropriate content, disrupting meetings or public displays.

Technical details

A rate-limiting bypass vulnerability exists in ESharePro versions through 7.6.0707. The application fails to properly restrict the frequency of connection attempts, allowing an attacker with local network access to perform a brute-force attack against the screen-sharing PIN or access code. Successful exploitation enables the attacker to establish an unauthorized session and cast arbitrary content to the screen. The vendor has released a security update to address this issue, and users are advised to update to the latest version.

Affected products

  • EShare ESharePro through 7.6.0707

Timeline

  • 2026-07-28: advisory: CSA Singapore and NVD published the advisory.
  • 2026-07-28: patched: Vendor released security updates.

References