CVE-2026-58056 Details
Description
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.
A vulnerability in RustDesk allows a peer with only file transfer authorization to bypass session restrictions and access control features meant for remote control sessions. This is possible because RustDesk improperly manages authorization flags, enabling unauthorized injection of keyboard and mouse inputs, as well as unmonitored screenshot and display capture requests.
Users are advised to update to the latest version of RustDesk, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 28, 2026CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bikini/exploitarium/tree/main/rustdesk-session-permission-pocs | [email protected] | BundleExploit |
| https://www.vulncheck.com/advisories/rustdesk-filetransfer-session-authorization-scope-bypass | [email protected] | AdvisoryBundleExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| RustDesk | <= ff226f6d8013dee2de5a6553abaf67bf32b3e875 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 18, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 28, 2026 | New CVE Received | [email protected] |
Volerion