Improper Invalidation in BetterDesk Affects Remote Desktop Management
CVE-2026-50575

7.7HIGH

Key Information:

Vendor

Unitronix

Vendor
CVE Published:
18 August 2026

What is CVE-2026-50575?

BetterDesk is a remote desktop management solution that contains a vulnerability allowing unauthenticated clients to bypass device registration controls. Versions up to 2.3.0 fail to properly invalidate deleted device identities, enabling potential replay or spoofing of device IDs. This could lead to unauthorized access to device management features. A patch has been implemented in version 3.0.0-alpha, but no workarounds are available for earlier versions.

Affected Version(s)

BetterDesk < 3.0.0-alpha

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.