CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-30783

Critical · CVSS 9.8

RustDesk Client — Privilege Abuse via client-side enforcement bypass (CWE-602, CWE-841) in API sync loop and config management

CVSS
9.8
nvd
EPSS
KEV
No
Class
kernel local
CWE-602, CWE-841

Description

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_mediator.Rs, src/hbbs_http/sync.Rs and program routines API sync loop, api-server config handling. This issue affects RustDesk Client: through 1.4.8.

Search profile — drives PoC discovery

Symbols src/rendezvous_mediator.rssrc/hbbs_http/sync.rsapi_sync_loopapi-server config handlingrendezvous_mediatorhbbs_httpsync.rsrustdesk-clientRendezvousMediatorapi_server
Keywords CVE-2026-30783RustDesk Client privilege abuserustdesk rendezvous_mediator exploitrustdesk hbbs_http sync vulnerabilityrustdesk api sync loop PoCrustdesk config management privilege escalationrustdesk client-side enforcement bypassrustdesk 1.4.8 vulnerabilityrustdesk CWE-602rustdesk CWE-841
Versions: through 1.4.8

References

Status: enriched · ingested 2026-06-22T12:00:15.000Z · profiled 2026-06-22T18:30:15.000Z