CVE-2026-50575
HIGH
7,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: low
Description
AI Translation Available
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.
294
Authentication Bypass by Capture-replay
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
345
Insufficient Verification of Data Authenticity
DraftCommon Consequences
Security Scopes Affected:
Integrity
Other
Potential Impacts:
Varies By Context
Unexpected State
Applicable Platforms
Technologies:
ICS/OT
672
Operation on a Resource after Expiration or Release
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Other
Availability
Potential Impacts:
Modify Application Data
Read Application Data
Other
Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies:
Mobile
https://github.com/UNITRONIX/BetterDesk/security/advisories/GHSA-3v82-3gf8-fxx8
https://github.com/UNITRONIX/BetterDesk/commit/f3b4df28240694b174158335e4c0c51c…
https://github.com/UNITRONIX/BetterDesk/security/advisories/GHSA-3v82-3gf8-fxx8