PT-2026-99108 · Rustdesk · Rustdesk

·

CVE-2026-100388

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions RustDesk versions prior to 1.5.0
Description On Linux and macOS, the Cliprdr message handler fails to properly validate file transfer permissions for incoming file clipboard messages. This allows authenticated remote peers, even those with file transfer permissions disabled, to place files onto the host clipboard and retrieve copied files and contents from the process-wide clipboard cache.
Recommendations Update to version 1.5.0 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100388

Affected Products

Rustdesk