CVE-2026-78835
Received Received - Intake

Rocket Remote Desktop Credentials Exposure

Vulnerability report for CVE-2026-78835, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

Rocket Software Rocket Remote Desktop 18.0.8583.1 is vulnerable to Insufficiently Protected Credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78835 is a vulnerability in Rocket Software's Rocket Remote Desktop 18.0.8583.1 where user credentials are stored insecurely. The software saves credentials in a configuration file called environments.xml with passwords encrypted using a static AES key. Additionally, user credentials are encrypted with either the user's SID or password as the key and IV. Attackers with system access can decrypt these credentials using routines from CommonHelper.dll and vSIT2.dll.

Detection Guidance

Check for the presence of the environments.xml file in Rocket Remote Desktop's configuration directory. Inspect the file for credentials encrypted with a static AES key. Use tools like strings or a hex editor to analyze CommonHelper.dll and vSIT2.dll for decryption routines.

Impact Analysis

This vulnerability allows attackers with access to a system running Rocket Remote Desktop to decrypt and view all stored user credentials, not just the current user's. This could lead to unauthorized access to sensitive accounts and data, especially in environments where low-privileged users can access high-privileged accounts. The risk is higher if multiple users share the same system.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, and other regulations that require protection of sensitive user data. Unauthorized access to credentials may result in data breaches, violating privacy and security requirements. Organizations using Rocket Remote Desktop may face legal and regulatory penalties for failing to safeguard user credentials.

Mitigation Strategies

Restrict access to the environments.xml file and Rocket Remote Desktop installation directory. Monitor for unauthorized access to these files. Consider temporarily disabling credential storage in Rocket Remote Desktop until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart