RustDesk addressed CVE-2026-57850 in version 1.4.9, fixing a server-side authorization flaw that let an authenticated peer in a limited session send control messages and login options intended only for a full Remote session. The vulnerability affects versions before 1.4.9 and could allow an attacker with low privileges to exceed the permissions granted for session types such as FileTransfer, PortForward, ViewCamera, or Terminal, potentially gaining broader visibility or control over the host. The issue is tracked as CWE-862 and carries a high-severity CVSS 3.1 score with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L.
The fix was introduced through pull request #15469 and commit 493b14ba78abc3dfb33f109c7f93c1c95a1dabc4, which enforce session-scoped permissions across authenticated connection types and block out-of-scope login, option, and control messages. RustDesk also added auditing and explicit close reasons for scoped-session violations, limited clipboard synchronization and screenshot handling to appropriate contexts, and prevented actions such as privacy mode or virtual display changes in view-camera sessions. The security changes were shipped as part of the broader 1.4.9 release.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-57850 was published describing a missing session scope enforcement issue in RustDesk before 1.4.9 that could let an authenticated remote peer exceed granted permissions and observe or control the host beyond the authorized scope.
RustDesk released version 1.4.9, the version referenced as fixing the session scope enforcement flaw affecting earlier releases.
RustDesk merged a commit implementing session-scope permission enforcement, adding auditing and close reasons for scoped-session violations and tightening controls for clipboard, screenshot, privacy mode, and display-related actions.
A RustDesk pull request introduced changes to enforce session-scoped permissions across authenticated connection types, restricting limited sessions to allowed message types and filtering out-of-scope login and option messages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.