Vulnerability Description
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config encryption, machine UID modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files hbb_common/src/password_security.Rs, hbb_common/src/config.Rs, hbb_common/src/lib.Rs (get_uuid), machine-uid/src/lib.Rs and program routines symmetric_crypt(), encrypt_str_or_original(), decrypt_str_or_original(), get_uuid(), get_machine_id(). This issue affects RustDesk Client: through 1.4.5.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rustdesk | Rustdesk | <= 1.4.5 |
| Apple | Macos | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPExploitThird Party Advisory
- https://github.com/rustdesk/rustdesk/discussions/4979Issue Tracking
- https://github.com/rustdesk/rustdesk/discussions/9229Issue Tracking
- https://www.vulsec.org/Not Applicable
FAQ
What is CVE-2026-30785?
CVE-2026-30785 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client ...
How severe is CVE-2026-30785?
CVE-2026-30785 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-30785?
Check the references section above for vendor advisories and patch information. Affected products include: Rustdesk Rustdesk, Apple Macos, Linux Linux Kernel, Microsoft Windows.