CVE-2026-79680
Received
Received - Intake
Authentication Bypass in Qt VNC Server
Vulnerability report for CVE-2026-79680, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-24
Last updated on: 2026-09-24
Assigner: TQtC
Description
Description
Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the confidentiality and integrity of the session.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qt | qt_vnc_server | * |
| axivion | axivion | From 7.8.5 (inc) to 7.8.12 (inc) |
| axivion | axivion | From 7.9.0 (inc) to 7.9.12 (inc) |
| axivion | axivion | From 7.10.0 (inc) to 7.10.10 (inc) |
| axivion | axivion | From 7.11.0 (inc) to 7.11.6 (inc) |
| axivion | axivion | From 7.12.0 (inc) to 7.12.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |