CVE-2026-30793
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-30793 is a Cross-Site Request Forgery (CSRF) vulnerability in the RustDesk Client that enables privilege escalation across all supported platforms. It affects RustDesk Client versions through 1.4.5 on Windows, macOS, Linux, iOS, and Android. The vulnerability was published on March 5, 2026, and was assigned by VULSec. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (Feedly, ENISA EUVD).

Technical details

The vulnerability is classified under CWE-352 (Cross-Site Request Forgery) and CWE-285 (Improper Authorization). It resides in the Flutter URI scheme handler (flutter/lib/common.dart) and the FFI bridge module (src/flutter_ffi.rs), specifically in the rustdesk://password/ URI handler and the bind.MainSetPermanentPassword() function. An attacker can craft a malicious rustdesk:// URI link that, when triggered by a victim (e.g., via a web page or phishing link), invokes the password-setting routine without any privilege check or CSRF token validation, allowing unauthorized modification of the permanent password. A Google Docs document titled 'RustDesk Details and PoCs' was referenced as a potential PoC but was found to contain no actual exploit content (Feedly, CVE.org).

Impact

Successful exploitation allows an attacker to silently change the victim's RustDesk permanent password, effectively taking over remote access credentials and enabling unauthorized remote desktop access to the victim's machine. The vulnerability has high confidentiality and integrity impacts — an attacker who sets a known password can subsequently connect to the victim's system and exfiltrate data, install malware, or pivot to other systems on the local network. Availability is not directly impacted by the CSRF itself, but the resulting unauthorized access could lead to full system compromise (Feedly, ENISA EUVD).

Exploitability

As of the time of reporting, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation. A referenced Google Docs PoC document was assessed as empty or inaccessible. The EPSS score is approximately 0.019% (0.000190), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).

Exploitation steps

  1. Reconnaissance: Identify targets running RustDesk Client version 1.4.5 or earlier on any supported platform (Windows, macOS, Linux, iOS, Android).
  2. Craft malicious URI: Construct a rustdesk://password/<attacker-chosen-password> URI that, when processed by the RustDesk client, invokes bind.MainSetPermanentPassword() with the attacker-supplied value.
  3. Deliver the payload: Embed the malicious URI in a web page, email, chat message, or document that the victim is likely to open (e.g., <a href="rustdesk://password/attacker123">Click here</a>).
  4. Trigger execution: When the victim clicks the link or the browser/OS automatically handles the URI scheme, the RustDesk client processes the request without verifying its origin or requiring user confirmation, setting the permanent password to the attacker's value.
  5. Gain remote access: Using the now-known permanent password, the attacker connects to the victim's RustDesk instance and achieves full remote desktop access (Feedly, Infinitsec).

Indicators of compromise

  • Network: Unexpected inbound RustDesk connection attempts from unknown IP addresses; outbound connections to RustDesk relay servers initiated shortly after a user clicked an external link.
  • Logs: RustDesk application logs showing rustdesk://password/ URI scheme invocations, particularly from browser or external process contexts; log entries for MainSetPermanentPassword() calls not initiated by the local user.
  • Process: RustDesk client process spawned or activated by a browser process (e.g., chrome.exe, firefox.exe, safari) rather than direct user interaction.
  • Configuration: Unexpected changes to the RustDesk permanent password setting in the application configuration file (e.g., ~/.config/rustdesk/RustDesk.toml on Linux, %APPDATA%\RustDesk\config\RustDesk.toml on Windows) with a timestamp not matching user activity.

Mitigation and workarounds

No official patch has been confirmed as released for this vulnerability; users should monitor RustDesk security advisories for a version beyond 1.4.5 that addresses this issue. As interim mitigations: disable or restrict the rustdesk:// URI scheme handler at the OS or browser level where remote desktop functionality is not required; implement network segmentation to limit inbound RustDesk connections; and train users to avoid clicking untrusted links. Organizations should monitor RustDesk logs for unexpected password change events and consider enforcing browser policies (e.g., disabling custom URI scheme handling) to reduce attack surface (Feedly, ENISA EUVD).

Community reactions

The vulnerability was noted on Bluesky via the CVE tracking account shortly after publication. Security aggregators including VulDB, CVEFeed, and Infinitsec covered the disclosure. The Infinitsec blog specifically highlighted the lack of privilege checks in the URI handler as the core design flaw. No official statement from the RustDesk development team has been publicly identified in response to this CVE (Infinitsec, Feedly).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-branding-upstream
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management