CVE Feed

    Dashboard / CVE / CVE-2026-30789

    CVE-2026-30789

    Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Password Brute Forcing. The authentication proof is SHA256(SHA256(password + salt) + challenge), where both the salt and the challenge are generated entirely by the server with no client-side nonce, and the hash uses no slow key-derivation function. A rogue or on-path API/relay server (see CVE-2026-30794 / CVE-2026-30797) can issue a chosen salt and challenge, capture the resulting proof, and recover the password offline. The capture-replay claim (CWE-294) is withdrawn: the challenge is regenerated per connection (challenge = Config::get_auto_password(6)), so a captured proof is not replayable against the legitimate server. The 1.4.7 OTP brute-force limiter and the existing LOGIN_FAILURES counter constrain only ONLINE attempts and do not address offline recovery. This vulnerability is associated with program files src/client.rs and program routines handle_hash(), handle_login_from_ui() (login proof construction). This issue affects RustDesk Client: through 1.4.8.

    Published:Mar 5, 2026
    Last Modified:Jun 22, 2026
    EPS:Mar 5, 2026
    EPSS Score:0.00377
    CVSS Score:9.8

    Affected Products

    Vendor
    Apple
    Product
    Iphone Os
    Vendor
    Apple
    Product
    Macos
    Vendor
    Google
    Product
    Android
    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Microsoft
    Product
    Windows
    Vendor
    Rustdesk
    Product
    Rustdesk
    Vendor
    Rustdesk-client
    Product
    Rustdesk Client

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High