CVE-2026-30785

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config encryption, machine UID modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files hbb_common/src/password_security.Rs, hbb_common/src/config.Rs, hbb_common/src/lib.Rs (get_uuid), machine-uid/src/lib.Rs and program routines symmetric_crypt(), encrypt_str_or_original(), decrypt_str_or_original(), get_uuid(), get_machine_id(). This issue affects RustDesk Client: through 1.4.5.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:-:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

25 Mar 2026, 15:47

Type Values Removed Values Added
Summary
  • (es) Modificación Inadecuadamente Controlada de Atributos de Prototipo de Objeto ('Contaminación de Prototipos'), vulnerabilidad de Uso de Hash de Contraseña Con Esfuerzo Computacional Insuficiente en rustdesk-client RustDesk Cliente rustdesk, hbb_common en Windows, MacOS, Linux (Módulo de seguridad de contraseña, cifrado de configuración, módulos de UID de máquina) permite Recuperar Datos Sensibles Incrustados. Esta vulnerabilidad está asociada con los archivos de programa hbb_common/src/password_security.Rs, hbb_common/src/config.Rs, hbb_common/src/lib.Rs (get_uuid), machine-uid/src/lib.Rs y las rutinas de programa symmetric_crypt(), encrypt_str_or_original(), decrypt_str_or_original(), get_uuid(), get_machine_id(). Este problema afecta a RustDesk Cliente: hasta la 1.4.5.
First Time Microsoft
Rustdesk rustdesk
Linux linux Kernel
Linux
Rustdesk
Microsoft windows
Apple macos
Apple
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:-:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
References () https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub - () https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub - Exploit, Third Party Advisory
References () https://github.com/rustdesk/rustdesk/discussions/4979 - () https://github.com/rustdesk/rustdesk/discussions/4979 - Issue Tracking
References () https://github.com/rustdesk/rustdesk/discussions/9229 - () https://github.com/rustdesk/rustdesk/discussions/9229 - Issue Tracking
References () https://www.vulsec.org/ - () https://www.vulsec.org/ - Not Applicable
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

05 Mar 2026, 19:16

Type Values Removed Values Added
References
  • () https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub -
  • () https://www.vulsec.org/ -

05 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 16:16

Updated : 2026-03-25 15:47


NVD link : CVE-2026-30785

Mitre link : CVE-2026-30785

CVE.ORG link : CVE-2026-30785


JSON object : View

Products Affected

rustdesk

  • rustdesk

microsoft

  • windows

apple

  • macos

linux

  • linux_kernel
CWE
CWE-257

Storing Passwords in a Recoverable Format

CWE-323

Reusing a Nonce, Key Pair in Encryption

CWE-916

Use of Password Hash With Insufficient Computational Effort

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')