Improper Invalidation in BetterDesk Affects Remote Desktop Management
CVE-2026-50575
7.7HIGH
What is CVE-2026-50575?
BetterDesk is a remote desktop management solution that contains a vulnerability allowing unauthenticated clients to bypass device registration controls. Versions up to 2.3.0 fail to properly invalidate deleted device identities, enabling potential replay or spoofing of device IDs. This could lead to unauthorized access to device management features. A patch has been implemented in version 3.0.0-alpha, but no workarounds are available for earlier versions.
Affected Version(s)
BetterDesk < 3.0.0-alpha
