Threats Tagged 'cve-2026-30796'
View all threats tagged with 'cve-2026-30796'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-30796'
Click on any threat for detailed analysis and mitigation recommendations
RustDesk Server Pro versions prior to 1.7.6 have a vulnerability where sensitive information, specifically a preset address book password, is transmitted in cleartext via the address book sync API modules. This affects Windows, MacOS, and Linux versions of rustdesk-server-pro. No official patch or remediation information is provided in the available data. Join the discussion | GCVE Database | 03/05/2026, 18:31:37 UTC Added: 07/19/2026, 19:38:22 UTC |
0 Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks. The client places the preset address-book password verbatim into the heartbeat sync JSON body (src/hbbs_http/sync.rs). Over an intact HTTPS session it is not exposed in transit, but it is a reusable shared secret rather than a zero-knowledge proof, so it is recovered by any party that becomes the API endpoint - under the re-homed/rogue API server (CVE-2026-30797) - and the leaked credential then authorizes the server-side address book. This vulnerability is associated with program files src/hbbs_http/sync.rs and program routines heartbeat sync body builder (emits preset-address-book-password). This issue affects RustDesk Client: through 1.4.8. Join the discussion | CVE Database V5 | 03/05/2026, 15:30:39 UTC Added: 03/05/2026, 17:41:51 UTC |
Showing 1 to 2 of 2 results