Ad

CVE-2026-30784

HIGH CVSS 4.0: 8.8 EPSS 0.39%
Updated Mar 25, 2026
Rustdesk
Parameter Value
CVSS 8.8 (HIGH)
Affected Versions before 1.7.5
Type CWE-862 (Missing Authorization), CWE-306 (Missing Authentication for Critical Function)
Vendor Rustdesk
Public PoC No

Missing Authorization, Missing Authentication for Critical Function vulnerability in rustdesk-server RustDesk Server rustdesk-server, rustdesk-server-pro on hbbs/hbbr on all server platforms (Rendezvous server (hbbs), relay server (hbbr) modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_server.Rs, src/relay_server.Rs and program routines handle_punch_hole_request(), RegisterPeer handler, relay forwarding. This issue affects RustDesk Server: through 1.7.5, through 1.1.15.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Rustdesk Rustdesk_Server
cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:oss:*:*:*
<= 1.1.15
Rustdesk Rustdesk_Server
cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:pro:*:*:*
<= 1.7.5