
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30793 is a Cross-Site Request Forgery (CSRF) vulnerability in the RustDesk Client that enables privilege escalation across all supported platforms. It affects RustDesk Client versions through 1.4.5 on Windows, macOS, Linux, iOS, and Android. The vulnerability was published on March 5, 2026, and was assigned by VULSec. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (Feedly, ENISA EUVD).
The vulnerability is classified under CWE-352 (Cross-Site Request Forgery) and CWE-285 (Improper Authorization). It resides in the Flutter URI scheme handler (flutter/lib/common.dart) and the FFI bridge module (src/flutter_ffi.rs), specifically in the rustdesk://password/ URI handler and the bind.MainSetPermanentPassword() function. An attacker can craft a malicious rustdesk:// URI link that, when triggered by a victim (e.g., via a web page or phishing link), invokes the password-setting routine without any privilege check or CSRF token validation, allowing unauthorized modification of the permanent password. A Google Docs document titled 'RustDesk Details and PoCs' was referenced as a potential PoC but was found to contain no actual exploit content (Feedly, CVE.org).
Successful exploitation allows an attacker to silently change the victim's RustDesk permanent password, effectively taking over remote access credentials and enabling unauthorized remote desktop access to the victim's machine. The vulnerability has high confidentiality and integrity impacts — an attacker who sets a known password can subsequently connect to the victim's system and exfiltrate data, install malware, or pivot to other systems on the local network. Availability is not directly impacted by the CSRF itself, but the resulting unauthorized access could lead to full system compromise (Feedly, ENISA EUVD).
As of the time of reporting, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation. A referenced Google Docs PoC document was assessed as empty or inaccessible. The EPSS score is approximately 0.019% (0.000190), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
rustdesk://password/<attacker-chosen-password> URI that, when processed by the RustDesk client, invokes bind.MainSetPermanentPassword() with the attacker-supplied value.<a href="rustdesk://password/attacker123">Click here</a>).rustdesk://password/ URI scheme invocations, particularly from browser or external process contexts; log entries for MainSetPermanentPassword() calls not initiated by the local user.chrome.exe, firefox.exe, safari) rather than direct user interaction.~/.config/rustdesk/RustDesk.toml on Linux, %APPDATA%\RustDesk\config\RustDesk.toml on Windows) with a timestamp not matching user activity.No official patch has been confirmed as released for this vulnerability; users should monitor RustDesk security advisories for a version beyond 1.4.5 that addresses this issue. As interim mitigations: disable or restrict the rustdesk:// URI scheme handler at the OS or browser level where remote desktop functionality is not required; implement network segmentation to limit inbound RustDesk connections; and train users to avoid clicking untrusted links. Organizations should monitor RustDesk logs for unexpected password change events and consider enforcing browser policies (e.g., disabling custom URI scheme handling) to reduce attack surface (Feedly, ENISA EUVD).
The vulnerability was noted on Bluesky via the CVE tracking account shortly after publication. Security aggregators including VulDB, CVEFeed, and Infinitsec covered the disclosure. The Infinitsec blog specifically highlighted the lack of privilege checks in the URI handler as the core design flaw. No official statement from the RustDesk development team has been publicly identified in response to this CVE (Infinitsec, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."