CVE-2026-100417 is a low-severity vulnerability in RustDesk before version 1.5.0 on Windows. The issue allows authenticated peers to read files from the host clipboard due to a failure in enforcing the one-way file transfer option against peer clipboard file requests. Attackers can exploit this by sending specific messages to retrieve copied files.
CVE-2026-100388 is a medium-severity vulnerability affecting RustDesk versions before 1.5.0. The issue arises from improper validation of file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions can exploit this to place files onto the host clipboard and retrieve copied files and cont [truncated]
A path traversal vulnerability exists in RustDesk versions 1.3.9 through 1.4.9, specifically in the macOS clipboard file-paste code path. This allows a remote peer in an active clipboard file-paste session to write files outside the intended target directory by using parent-directory components or absolute paths. The vulnerability is caused by the application's failure to properly validate and normalize f [truncated]
CVE-2026-76840 is a heap buffer overflow vulnerability in RustDesk's Windows clipboard redirection. A malicious peer can supply an oversized file contents response, causing attacker-chosen data to be written past the end of a paste consumer's heap buffer when the local user pastes clipboard file contents offered by the remote side. This issue arises from a lack of upper bound checking when copying a peer- [truncated]
CVE-2026-57850 is a high-severity vulnerability in RustDesk, a remote desktop application. The issue arises from the lack of server-side enforcement of session scope, allowing an authenticated remote peer to send control messages and login options reserved for a full Remote session, even if granted a limited session type. This vulnerability could allow an attacker to observe and control the host beyond th [truncated]
CVE-2026-58056 is a HIGH-severity vulnerability in RustDesk, a remote desktop application. The issue arises from RustDesk's gating of incoming control messages on per-capability flags rather than on the session's authorized connection type. Specifically, a file-transfer session does not clear those flags, allowing a peer with only a valid FileTransfer authorization to inject keyboard and mouse input and a [truncated]