CVE-2026-57850 is a high-severity vulnerability in RustDesk, a remote desktop application. The issue arises from the lack of server-side enforcement of session scope, allowing an authenticated remote peer to send control messages and login options reserved for a full Remote session, even if granted a limited session type. This vulnerability could allow an attacker to observe and control the host beyond th [truncated]
CVE-2026-58056 is a HIGH-severity vulnerability in RustDesk, a remote desktop application. The issue arises from RustDesk's gating of incoming control messages on per-capability flags rather than on the session's authorized connection type. Specifically, a file-transfer session does not clear those flags, allowing a peer with only a valid FileTransfer authorization to inject keyboard and mouse input and a [truncated]