CVE-2026-50575

Summary

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.

Affected Software

VendorProductVersion RangeStatus
UNITRONIXBetterDesk< 3.0.0-alphaaffected

Weaknesses

  • CWE-294: CWE-294: Authentication Bypass by Capture-replay
  • CWE-345: CWE-345: Insufficient Verification of Data Authenticity
  • CWE-672: CWE-672: Operation on a Resource after Expiration or Release

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: total

Additional References

References