
Same release, server side: an RDSTLS auth bypass (CVE-2026-73241, 8.3). RDSTLS_RESULT_SUCCESS is 0x00000000. The context comes from calloc. Reach the verdict without ever sending credentials and resultCode is still 0 — already "success." 3.30.0 defaults it to ACCESS_DENIED. https://t.co/KwYHOZLrPd
Post summary
The post describes an RDSTLS authentication bypass in a server release, detailing how a success code can be achieved without credentials, and notes the 3.30.0 default to ACCESS_DENIED as a mitigation, but provides no exploit code or evidence of active attacks.
