CVE-2026-30796

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Address book sync API modules) allows Sniffing Attacks. This vulnerability is associated with program files Closed source — API endpoint handling heartbeat sync and program routines Heartbeat API handler (accepts preset-address-book-password in plaintext). This issue affects RustDesk Server Pro: through 1.7.5.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:pro:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

25 Mar 2026, 17:50

Type Values Removed Values Added
CPE cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:webclient:*:*:*

25 Mar 2026, 14:51

Type Values Removed Values Added
References () https://www.vulsec.org/ - Product () https://www.vulsec.org/ - Not Applicable

25 Mar 2026, 14:41

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Microsoft
Rustdesk rustdesk
Rustdesk rustdesk Server
Linux linux Kernel
Linux
Rustdesk
Microsoft windows
Apple macos
Apple
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:pro:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:webclient:*:*:*
References () https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub - () https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub - Exploit, Third Party Advisory
References () https://rustdesk.com/docs/en/ - () https://rustdesk.com/docs/en/ - Product, Vendor Advisory
References () https://www.vulsec.org/ - () https://www.vulsec.org/ - Product
Summary
  • (es) Vulnerabilidad de transmisión en texto claro de información sensible en rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro en Windows, MacOS, Linux (Módulos de API de sincronización de libreta de direcciones) permite ataques de sniffing. Esta vulnerabilidad está asociada con archivos de programa de código cerrado — punto final de API que gestiona la sincronización de latidos y rutinas de programa gestor de API de latidos (acepta preset-address-book-password en texto claro). Este problema afecta a RustDesk Server Pro: hasta la 1.7.5.

05 Mar 2026, 19:16

Type Values Removed Values Added
References
  • () https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub -
  • () https://www.vulsec.org/ -

05 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 16:16

Updated : 2026-03-25 17:50


NVD link : CVE-2026-30796

Mitre link : CVE-2026-30796

CVE.ORG link : CVE-2026-30796


JSON object : View

Products Affected

rustdesk

  • rustdesk_server

linux

  • linux_kernel

microsoft

  • windows

apple

  • macos
CWE
CWE-319

Cleartext Transmission of Sensitive Information