Improper Certificate Validation in RustDesk Client by RustDesk
CVE-2026-30794
Key Information:
- Vendor
Rustdesk-client
- Status
- Vendor
- CVE Published:
- 5 March 2026
Badges
What is CVE-2026-30794?
The RustDesk Client exhibits an improper certificate validation vulnerability, stemming from its handling of TLS transport modules across various platforms including Windows, MacOS, Linux, iOS, and Android. When adversaries intercept communications, they can exploit this flaw, allowing unauthorized access or manipulation of data. The issue arises from certain program files and routines that permit dangerous configurations, notably allowing invalid certificates to be accepted during TLS connections. As such, users of RustDesk Client versions up to 1.4.5 need to address this vulnerability to enhance their security posture.
Affected Version(s)
RustDesk Client Windows 0 <= 1.4.5
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
