
PEACH
Un cadre d’isolation des locataires
CVE-2026-79680 is an authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB (Remote Framebuffer) protocol can bypass password authentication and gain unauthorized remote access to the shared application. The vulnerability affects Qt versions 6.4.0 through 6.8.8 and 6.9.0 through 6.11.2. It was disclosed on September 24, 2026, and carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 4.5 (Medium) (Red Hat Advisory, GitHub Advisory).
The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and CWE-358 (Improperly Implemented Security Check for Standard), indicating that the Qt VNC Server's RFB protocol implementation fails to properly enforce password authentication when a client deviates from expected protocol behavior (GitHub Advisory, Red Hat Bugzilla). An attacker crafts a modified VNC client that intentionally violates the RFB protocol handshake or authentication exchange in a way that causes the server to skip or incorrectly validate the password check. The attack vector is network-based, requires no privileges, and exploitation requires attack prerequisites to be present (e.g., an active VNC session or specific server configuration). A patch commit is publicly referenced in the Qt project code review system (GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to gain full access to the application shared via Qt VNC Server, compromising both confidentiality and integrity of the session. The attacker can read sensitive data displayed within the shared application and manipulate or modify the application's state and behavior without authorization. Availability is not directly impacted by this vulnerability, and there is no lateral movement to subsequent systems beyond the shared application scope (Red Hat Advisory, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.342%, indicating a low near-term probability of exploitation. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat Advisory).
Qt has released patched versions addressing this vulnerability: upgrade to Qt 6.8.9 or later for the 6.4–6.8 branch, or to Qt 6.11.3 or later for the 6.9–6.11 branch (Red Hat Advisory, GitHub Advisory). The patch is available for review at the Qt project code review system. As a temporary workaround until patching is completed, restrict network access to Qt VNC Server instances to trusted networks only using firewall rules or network segmentation, and avoid exposing VNC ports to the public internet.
Red Hat has tracked the vulnerability via their security advisory and Bugzilla system, assigning it medium priority and severity in their internal triage (Red Hat Advisory, Red Hat Bugzilla). The GitHub Advisory Database has published the advisory as "Moderate" severity based on the CVSS v4.0 score. No significant broader community discussion, researcher commentary, or media coverage has been identified at this time.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."