CVE-2026-50575

Published: Ago 18, 2026 Last Modified: Ago 18, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,7
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: low

Description

AI Translation Available

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.

294

Authentication Bypass by Capture-replay

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
345

Insufficient Verification of Data Authenticity

Draft
Common Consequences
Security Scopes Affected:
Integrity Other
Potential Impacts:
Varies By Context Unexpected State
Applicable Platforms
Technologies: ICS/OT
View CWE Details
672

Operation on a Resource after Expiration or Release

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Other Availability
Potential Impacts:
Modify Application Data Read Application Data Other Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies: Mobile
View CWE Details
https://github.com/UNITRONIX/BetterDesk/security/advisories/GHSA-3v82-3gf8-fxx8
https://github.com/UNITRONIX/BetterDesk/commit/f3b4df28240694b174158335e4c0c51c…
https://github.com/UNITRONIX/BetterDesk/security/advisories/GHSA-3v82-3gf8-fxx8