CVE-2026-30783
Critical · CVSS 9.8RustDesk Client — Privilege Abuse via client-side enforcement bypass (CWE-602, CWE-841) in API sync loop and config management
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- kernel local
- CWE-602, CWE-841
Description
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_mediator.Rs, src/hbbs_http/sync.Rs and program routines API sync loop, api-server config handling. This issue affects RustDesk Client: through 1.4.8.
Search profile — drives PoC discovery
Symbols src/rendezvous_mediator.rssrc/hbbs_http/sync.rsapi_sync_loopapi-server config handlingrendezvous_mediatorhbbs_httpsync.rsrustdesk-clientRendezvousMediatorapi_server
Keywords CVE-2026-30783RustDesk Client privilege abuserustdesk rendezvous_mediator exploitrustdesk hbbs_http sync vulnerabilityrustdesk api sync loop PoCrustdesk config management privilege escalationrustdesk client-side enforcement bypassrustdesk 1.4.8 vulnerabilityrustdesk CWE-602rustdesk CWE-841
Versions: through 1.4.8
References
Status: enriched · ingested 2026-06-22T12:00:15.000Z · profiled 2026-06-22T18:30:15.000Z