CVE-2026-58056Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-28); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-28: 1Mentions · 2026-06-29: 1Technical Details · 2026-06-28: 1Technical Details · 2026-06-29: 106-2806-29
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-281
Disclosure1
2026-06-291
General1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-58056 Privilege Escalation in RustDesk via Uncleared FileTransfer Session Capability Flags https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-58056

    Post summary

    RustDesk has a privilege‑escalation vulnerability (CVE‑2026‑58056) caused by improperly handled file‑transfer session capability flags.

    00010140
    4.1K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    General

    CVE-2026-58056 RustDesk Incorrect authorisation could let attackers access beyond the authorised session, turning remote access tooling into a wider endpoint-control risk Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-28/TIER_2_CVE-2026-58056.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement

    Post summary

    An authorization flaw in RustDesk (CVE‑2026‑58056) could allow attackers to expand session privileges; the report provides technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    0000061
    56 followersView on X

Explore more