CVE-2026-79680: 
Qt Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-79680 is an authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB (Remote Framebuffer) protocol can bypass password authentication and gain unauthorized remote access to the shared application. The vulnerability affects Qt versions 6.4.0 through 6.8.8 and 6.9.0 through 6.11.2. It was disclosed on September 24, 2026, and carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 4.5 (Medium) (Red Hat Advisory, GitHub Advisory).

Détails techniques

The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and CWE-358 (Improperly Implemented Security Check for Standard), indicating that the Qt VNC Server's RFB protocol implementation fails to properly enforce password authentication when a client deviates from expected protocol behavior (GitHub Advisory, Red Hat Bugzilla). An attacker crafts a modified VNC client that intentionally violates the RFB protocol handshake or authentication exchange in a way that causes the server to skip or incorrectly validate the password check. The attack vector is network-based, requires no privileges, and exploitation requires attack prerequisites to be present (e.g., an active VNC session or specific server configuration). A patch commit is publicly referenced in the Qt project code review system (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to gain full access to the application shared via Qt VNC Server, compromising both confidentiality and integrity of the session. The attacker can read sensitive data displayed within the shared application and manipulate or modify the application's state and behavior without authorization. Availability is not directly impacted by this vulnerability, and there is no lateral movement to subsequent systems beyond the shared application scope (Red Hat Advisory, GitHub Advisory).

Exploitabilité

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.342%, indicating a low near-term probability of exploitation. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify hosts running Qt VNC Server (versions 6.4.0–6.8.8 or 6.9.0–6.11.2) exposed on the network, typically listening on TCP port 5900 or similar VNC ports, using tools such as Shodan, Censys, or Nmap.
  2. Craft a modified VNC client: Develop or modify an existing VNC client to intentionally violate the RFB protocol during the authentication phase — for example, by sending malformed or out-of-sequence authentication messages that the Qt VNC Server fails to properly reject.
  3. Initiate connection: Connect the modified VNC client to the target Qt VNC Server instance and begin the RFB protocol handshake.
  4. Bypass authentication: Send the crafted protocol-violating authentication sequence that exploits the server's improper security check (CWE-358), causing the server to skip or incorrectly validate the password requirement.
  5. Gain unauthorized access: Upon successful bypass, the attacker obtains a full VNC session to the shared application, enabling them to view sensitive on-screen data and interact with the application as if authenticated (Red Hat Bugzilla, GitHub Advisory).

Indicateurs de compromis

  • Network: Unexpected or anomalous VNC connections (TCP port 5900/5901) from unknown or untrusted IP addresses to hosts running Qt applications; VNC traffic exhibiting malformed or non-standard RFB protocol handshake sequences detectable via deep packet inspection.
  • Logs: Qt VNC Server logs showing successful session establishment without a corresponding valid authentication event; connection attempts with protocol errors or unexpected message ordering during the authentication phase.
  • Process: Unexpected mouse/keyboard input events or screen changes on the host running the Qt VNC Server application that do not correspond to local user activity, indicating a remote session is active.

Atténuation et solutions de contournement

Qt has released patched versions addressing this vulnerability: upgrade to Qt 6.8.9 or later for the 6.4–6.8 branch, or to Qt 6.11.3 or later for the 6.9–6.11 branch (Red Hat Advisory, GitHub Advisory). The patch is available for review at the Qt project code review system. As a temporary workaround until patching is completed, restrict network access to Qt VNC Server instances to trusted networks only using firewall rules or network segmentation, and avoid exposing VNC ports to the public internet.

Réactions de la communauté

Red Hat has tracked the vulnerability via their security advisory and Bugzilla system, assigning it medium priority and severity in their internal triage (Red Hat Advisory, Red Hat Bugzilla). The GitHub Advisory Database has published the advisory as "Moderate" severity based on the CVSS v4.0 score. No significant broader community discussion, researcher commentary, or media coverage has been identified at this time.

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Qt Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-19395MEDIUM6.6
  • Qt logoQt
  • qt6
NonNonOct 05, 2026
CVE-2026-76151MEDIUM4.6
  • Qt logoQt
  • qt5-qtbase
NonOuiSep 16, 2026
CVE-2026-79680MEDIUM4.5
  • Qt logoQt
  • cpe:2.3:a:qt:qt
NonOuiSep 24, 2026
CVE-2026-78253LOW2.3
  • Qt logoQt
  • qt6.src
NonOuiSep 23, 2026
CVE-2026-79616LOW0.6
  • Qt logoQt
  • qt5-qtdeclarative-examples
NonOuiSep 23, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités