CVE-2026-100388
Deferred Deferred - Pending Action

RustDesk File Transfer Permission Bypass on Linux and macOS

Vulnerability report for CVE-2026-100388, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: VulnCheck

Description

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions can place files onto the host clipboard and retrieve copied files and contents from the process-wide clipboard cache.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rustdesk rustdesk to 1.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

RustDesk versions before 1.5.0 do not properly check file transfer permissions when receiving clipboard messages on Linux and macOS. This allows authenticated remote users with disabled file transfer permissions to place files on the host clipboard and access copied files or clipboard contents from the process-wide cache.

Detection Guidance

Detecting this vulnerability requires checking RustDesk versions and monitoring clipboard activity. Verify installed version with 'rustdesk --version' and compare against 1.5.0. Check clipboard permissions in RustDesk settings for file transfer restrictions.

Impact Analysis

An attacker could steal sensitive clipboard data or place malicious files on your system through the clipboard, even if file transfers are disabled. This could lead to data theft, malware execution, or unauthorized access to copied information.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, potentially violating GDPR (data protection) or HIPAA (health information privacy) if sensitive data is leaked via the clipboard. Organizations may face compliance penalties if this issue is exploited.

Mitigation Strategies

Upgrade RustDesk to version 1.5.0 or later immediately. Disable file transfer permissions in RustDesk settings for all users. Monitor network traffic for unexpected clipboard data transfers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100388. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart