PT-2026-23465 · Unknown · Rustdesk Server

Erez Kalman

·

Published

2026-03-05

·

Updated

2026-03-05

·

CVE-2026-30784

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RustDesk Server versions through 1.7.5 RustDesk Server versions through 1.1.15
Description A missing authorization and authentication issue exists in the RustDesk Server’s Rendezvous server (hbbs) and relay server (hbbr) modules, potentially allowing privilege abuse. The issue is present in the src/rendezvous server.rs and src/relay server.rs program files, specifically within the handle punch hole request() function and the RegisterPeer handler, as well as relay forwarding routines.
Recommendations Update RustDesk Server to a version later than 1.7.5. Update RustDesk Server to a version later than 1.1.15.

Exploit

Fix

Missing Authorization

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-30784

Affected Products

Rustdesk Server