Security-policy override via unsigned strategy payloads
Published Mar 5, 2026 · Updated Mar 5, 2026
RustDesk Client 1.4.8 and earlier allows attackers to override local security settings through a subverted API channel. The strategy merge loop accepts unsigned config_options from the configured API heartbeat and passes them to Config::set_options(), which applies strategy values above user settings and ignores the local remote-modification toggle. Exploitation requires plaintext HTTP, a compromised or rogue API endpoint, client re-homing, or nondefault insecure TLS fallback; it can clear whitelists or enable full control, file transfer, terminal, and other restricted features.
Summary
What happened
RustDesk Client 1.4.8 and earlier allows attackers to override local security settings through a subverted API channel. The strategy merge loop accepts unsigned config_options from the configured API heartbeat and passes them to Config::set_options(), which applies strategy values above user settings and ignores the local remote-modification toggle. Exploitation requires plaintext HTTP, a compromised or rogue API endpoint, client re-homing, or nondefault insecure TLS fallback; it can clear whitelists or enable full control, file transfer, terminal, and other restricted features.
The record
- CVE
- CVE-2026-30792
- Published
- Mar 5, 2026
- Updated
- Mar 5, 2026
- Vendor
- RustDesk
- Product
- RustDesk
- Classifications
- CWE-345, CAPEC-384, T1557
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Mar 5, 2026CVE publishedPublication date reported by the CVE source.
- Mar 5, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <=1.4.5
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Strategy Hijack - Whitelist/ACL Bypass PoCproof of concept · unverified
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo