CVE-2026-30795: Rustdesk
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines Heartbeat JSON payload construction (preset-address-book-password). This issue affects RustDesk Client: through 1.4.5.
Affected products
- Rustdesk Rustdesk: up to and including 1.4.5
Published 2026-03-05. Last modified 2026-06-17.