CVE-2026-30784

Missing Authorization, Missing Authentication for Critical Function vulnerability in rustdesk-server RustDesk Server rustdesk-server, rustdesk-server-pro on hbbs/hbbr on all server platforms (Rendezvous server (hbbs), relay server (hbbr) modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_server.Rs, src/relay_server.Rs and program routines handle_punch_hole_request(), RegisterPeer handler, relay forwarding. This issue affects RustDesk Server: through 1.7.5, through 1.1.15.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:oss:*:*:*
cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:pro:*:*:*

History

25 Mar 2026, 16:19

Type Values Removed Values Added
CPE cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:oss:*:*:*
cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:pro:*:*:*
References () https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub - () https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub - Exploit, Third Party Advisory
References () https://rustdesk.com/docs/en/self-host/ - () https://rustdesk.com/docs/en/self-host/ - Product, Vendor Advisory
References () https://www.vulsec.org/ - () https://www.vulsec.org/ - Not Applicable
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Rustdesk
Rustdesk rustdesk Server
Summary
  • (es) Vulnerabilidad de Autorización Faltante, Autenticación Faltante para Función Crítica en rustdesk-server RustDesk Server rustdesk-server, rustdesk-server-pro en hbbs/hbbr en todas las plataformas de servidor (módulos de servidor Rendezvous (hbbs), servidor de retransmisión (hbbr)) permite el Abuso de Privilegios. Esta vulnerabilidad está asociada con los archivos de programa src/rendezvous_server.Rs, src/relay_server.Rs y las rutinas de programa handle_punch_hole_request(), el gestor RegisterPeer, el reenvío de retransmisión. Este problema afecta a RustDesk Server: hasta 1.7.5, hasta 1.1.15.

05 Mar 2026, 19:16

Type Values Removed Values Added
References
  • () https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub -
  • () https://www.vulsec.org/ -

05 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 16:16

Updated : 2026-03-25 16:19


NVD link : CVE-2026-30784

Mitre link : CVE-2026-30784

CVE.ORG link : CVE-2026-30784


JSON object : View

Products Affected

rustdesk

  • rustdesk_server
CWE
CWE-306

Missing Authentication for Critical Function

CWE-862

Missing Authorization