← Retour aux CVEs
CVE-2026-30792
HIGH8.1
Description
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files src/hbbs_http/sync.Rs, hbb_common/src/config.Rs and program routines Strategy merge loop in sync.Rs, Config::set_options(). This issue affects RustDesk Client: through 1.4.5.
Details CVE
Score CVSS v3.18.1
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurNONE
Publie3/5/2026
Derniere modification3/25/2026
Sourcenvd
Observations honeypot0
Produits affectes
apple:iphone_osapple:macosgoogle:androidlinux:linux_kernelmicrosoft:windowsrustdesk:rustdesk
Faiblesses (CWE)
CWE-657
References
https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub(2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe)
https://rustdesk.com/docs/en/self-host/client-configuration/advanced-settings/(2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe)
https://www.vulsec.org/(2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.