Authentication Bypass in Qt VNC Server Module Affects Remote Access Functionality
CVE-2026-79680

4.5MEDIUM

Key Information:

Vendor

Qt

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-79680?

The vulnerability in the password authentication mechanism of the Qt VNC Server module allows attackers to exploit a specially modified VNC client that deviates from the RFB protocol. This exploitation facilitates the circumvention of password authentication, granting unauthorized remote access to shared applications. Such access jeopardizes the confidentiality and integrity of active sessions, posing significant risks to affected systems.

Affected Version(s)

qt 6.4.0 < 6.8.9

qt 6.9.0 < 6.11.3

References

CVSS V4

Score:
4.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.