CVE-2026-30796General(apple / linux_kernel)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks. The client places the preset address-book password verbatim into the heartbeat sync JSON body (src/hbbs_http/sync.rs). Over an intact HTTPS session it is not exposed in transit, but it is a reusable shared secret rather than a zero-knowledge proof, so it is recovered by any party that becomes the API endpoint - under the re-homed/rogue API server (CVE-2026-30797) - and the leaked credential then authorizes the server-side address book. This vulnerability is associated with program files src/hbbs_http/sync.rs and program routines heartbeat sync body builder (emits preset-address-book-password). This issue affects RustDesk Client: through 1.4.8.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Other references
Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel
  • macos
  • rustdesk_server
  • windows

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
linux_kernelmacosrustdesk_serverwindows

1 version affected across 4 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-05: 2Technical Details · 2026-03-05: 103-05
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-30796 Cleartext Transmission of Sensitive Information vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Address book sy… https://www.cve.org/CVERecord?id=CVE-2026-30796

    Post summary

    The text simply references CVE-2026-30796, noting a cleartext transmission issue in RustDesk Server Pro across multiple OSes, but provides no further technical details, exploit code, or patch information.

    00000129
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30796 Intel Report: https://ift.tt/5zVojIx

    Post summary

    A brief alert references CVE-2026-30796 but gives no technical, exploit, or mitigation details.

    0000034
    343 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
OSlinuxlinux_kernel---
OSmicrosoftwindows---
Apprustdeskrustdesk_server---

Explore more