CVE-2026-15682
AnyDesk vulnerability analysis and mitigation

Overview

CVE-2026-15682 is a link-following denial-of-service vulnerability in AnyDesk's "Send Support Information" feature that allows local, low-privileged attackers to create arbitrary files via Windows junction abuse, resulting in a denial-of-service condition. The vulnerability was reported to AnyDesk on March 30, 2025, and publicly disclosed by the Zero Day Initiative (ZDI) on July 8, 2026, after the vendor failed to provide a fix within the coordinated disclosure window — ultimately published as a 0-day advisory (ZDI Advisory). The confirmed affected version is AnyDesk 9.0.4. The CVSS v3.1 base score is 5.5 (Medium) per NVD, while ZDI and GitHub Advisory assign a score of 4.7 (Medium) using a higher attack complexity rating (GitHub Advisory, ZDI Advisory).

Technical details

The root cause is CWE-59 (Improper Link Resolution Before File Access — 'Link Following'), where the AnyDesk service does not properly validate filesystem paths before accessing them during the "Send Support Information" operation (GitHub Advisory). An attacker with low-privileged local code execution can create a Windows directory junction (a type of filesystem symlink) pointing to an arbitrary target location; when the AnyDesk service processes the support information request, it follows the junction and creates files at the attacker-controlled path (ZDI Advisory). This file creation in unintended locations can corrupt critical system resources, triggering a denial-of-service condition. The attack requires no user interaction and no elevated privileges beyond initial local code execution access.

Impact

Successful exploitation results in a denial-of-service condition on the affected system, with high availability impact and no confidentiality or integrity impact (ZDI Advisory). By causing arbitrary file creation in sensitive directories, an attacker can render the system or specific services unavailable, disrupting remote access capabilities provided by AnyDesk. The scope is limited to the local system (unchanged scope), and there is no evidence of lateral movement potential or data exposure risk associated with this vulnerability (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (ZDI Advisory). The vulnerability was discovered by researcher Giuliano Sanfins from SiDi (0x_alibabas) and reported through the ZDI program. The EPSS score is approximately 0.10–0.13%, placing it in the 3rd percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" and automation as "no" (ZDI Advisory). The high attack complexity (AC:H) rating reflects the timing and setup requirements for successful junction exploitation.

Exploitation steps

  1. Gain local access: Obtain low-privileged code execution on a system running AnyDesk 9.0.4 (e.g., via phishing, existing malware, or a compromised local account).
  2. Identify the target path: Determine the directory path used by AnyDesk's "Send Support Information" feature when writing temporary or log files (typically within the AnyDesk application data directory, e.g., %APPDATA%\AnyDesk\ or a system temp path).
  3. Create a Windows junction: Before triggering the support information feature, create a directory junction at the expected output path pointing to a sensitive target directory (e.g., using mklink /J C:\path\to\anydesk\output C:\Windows\System32\ or similar).
  4. Trigger the vulnerable feature: Invoke the "Send Support Information" function within AnyDesk, causing the service to follow the junction and write files to the attacker-controlled target path.
  5. Achieve denial-of-service: The arbitrary file creation in the redirected sensitive directory corrupts or overwrites critical files, causing the targeted service or system to become unavailable (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected files created in sensitive system directories (e.g., C:\Windows\System32\, C:\Windows\Temp\) originating from the AnyDesk process; presence of directory junctions in AnyDesk application data paths (e.g., %APPDATA%\AnyDesk\ or %PROGRAMDATA%\AnyDesk\) pointing to unrelated system directories.
  • Process: AnyDesk service (AnyDesk.exe) spawning file write operations to directories outside its normal application scope; unusual file creation events logged by endpoint detection tools associated with the AnyDesk process.
  • Logs: Windows Event Log entries (Event ID 4663 — file system object access) showing AnyDesk writing to unexpected directories; filesystem audit logs recording junction creation by a low-privileged user account shortly before AnyDesk support information events.
  • Network: No specific network-based IOCs are associated with this local exploitation vector.

Mitigation and workarounds

ZDI notes that given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the affected product until a vendor patch is available (ZDI Advisory). A patch is referenced via GitHub Advisory GHSA-f5mf-mx82-hm83 (added July 14, 2026), though specific fixed version details are not yet listed in the advisory (GitHub Advisory). As interim workarounds: restrict the "Send Support Information" feature to trusted administrators only, limit local user access on systems running AnyDesk 9.0.4, and monitor for suspicious junction creation activity in AnyDesk application directories. Organizations should check AnyDesk's official release channel for a patched version and apply it promptly.

Community reactions

The vulnerability received moderate coverage from cybersecurity news outlets, with several publications describing it as a "zero-day" due to AnyDesk's failure to patch within the coordinated disclosure window (CyberSecurityNews, GBHackers). VPNcentral noted this was one of two AnyDesk zero-day flaws disclosed around the same time allowing local attackers to cause denial-of-service (VPNcentral). The Hacker News included it in their weekly recap for the week of July 2026 (The Hacker News). Community sentiment on social media (X/Twitter, Mastodon) was generally focused on the vendor's lack of responsiveness during the 15+ month disclosure timeline before ZDI published as a 0-day advisory.

Additional resources


SourceThis report was generated using AI

Related AnyDesk vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2016-20094HIGH8.5
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesJun 19, 2026
CVE-2019-25261HIGH8.5
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesFeb 03, 2026
CVE-2025-34499MEDIUM6.9
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesDec 11, 2025
CVE-2026-15682MEDIUM5.5
  • AnyDesk logoAnyDesk
  • anydesk
NoYesJul 13, 2026
CVE-2026-15681MEDIUM5.5
  • AnyDesk logoAnyDesk
  • anydesk
NoYesJul 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management