
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-15682 is a link-following denial-of-service vulnerability in AnyDesk's "Send Support Information" feature that allows local, low-privileged attackers to create arbitrary files via Windows junction abuse, resulting in a denial-of-service condition. The vulnerability was reported to AnyDesk on March 30, 2025, and publicly disclosed by the Zero Day Initiative (ZDI) on July 8, 2026, after the vendor failed to provide a fix within the coordinated disclosure window — ultimately published as a 0-day advisory (ZDI Advisory). The confirmed affected version is AnyDesk 9.0.4. The CVSS v3.1 base score is 5.5 (Medium) per NVD, while ZDI and GitHub Advisory assign a score of 4.7 (Medium) using a higher attack complexity rating (GitHub Advisory, ZDI Advisory).
The root cause is CWE-59 (Improper Link Resolution Before File Access — 'Link Following'), where the AnyDesk service does not properly validate filesystem paths before accessing them during the "Send Support Information" operation (GitHub Advisory). An attacker with low-privileged local code execution can create a Windows directory junction (a type of filesystem symlink) pointing to an arbitrary target location; when the AnyDesk service processes the support information request, it follows the junction and creates files at the attacker-controlled path (ZDI Advisory). This file creation in unintended locations can corrupt critical system resources, triggering a denial-of-service condition. The attack requires no user interaction and no elevated privileges beyond initial local code execution access.
Successful exploitation results in a denial-of-service condition on the affected system, with high availability impact and no confidentiality or integrity impact (ZDI Advisory). By causing arbitrary file creation in sensitive directories, an attacker can render the system or specific services unavailable, disrupting remote access capabilities provided by AnyDesk. The scope is limited to the local system (unchanged scope), and there is no evidence of lateral movement potential or data exposure risk associated with this vulnerability (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (ZDI Advisory). The vulnerability was discovered by researcher Giuliano Sanfins from SiDi (0x_alibabas) and reported through the ZDI program. The EPSS score is approximately 0.10–0.13%, placing it in the 3rd percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" and automation as "no" (ZDI Advisory). The high attack complexity (AC:H) rating reflects the timing and setup requirements for successful junction exploitation.
%APPDATA%\AnyDesk\ or a system temp path).mklink /J C:\path\to\anydesk\output C:\Windows\System32\ or similar).C:\Windows\System32\, C:\Windows\Temp\) originating from the AnyDesk process; presence of directory junctions in AnyDesk application data paths (e.g., %APPDATA%\AnyDesk\ or %PROGRAMDATA%\AnyDesk\) pointing to unrelated system directories.AnyDesk.exe) spawning file write operations to directories outside its normal application scope; unusual file creation events logged by endpoint detection tools associated with the AnyDesk process.ZDI notes that given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the affected product until a vendor patch is available (ZDI Advisory). A patch is referenced via GitHub Advisory GHSA-f5mf-mx82-hm83 (added July 14, 2026), though specific fixed version details are not yet listed in the advisory (GitHub Advisory). As interim workarounds: restrict the "Send Support Information" feature to trusted administrators only, limit local user access on systems running AnyDesk 9.0.4, and monitor for suspicious junction creation activity in AnyDesk application directories. Organizations should check AnyDesk's official release channel for a patched version and apply it promptly.
The vulnerability received moderate coverage from cybersecurity news outlets, with several publications describing it as a "zero-day" due to AnyDesk's failure to patch within the coordinated disclosure window (CyberSecurityNews, GBHackers). VPNcentral noted this was one of two AnyDesk zero-day flaws disclosed around the same time allowing local attackers to cause denial-of-service (VPNcentral). The Hacker News included it in their weekly recap for the week of July 2026 (The Hacker News). Community sentiment on social media (X/Twitter, Mastodon) was generally focused on the vendor's lack of responsiveness during the 15+ month disclosure timeline before ZDI published as a 0-day advisory.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."