BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unitronix
Unitronix betterdesk |
|
| Vendors & Products |
Unitronix
Unitronix betterdesk |
Tue, 18 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available. | |
| Title | BetterDesk has a replay behavior vulnerability when devices are deleted | |
| Weaknesses | CWE-294 CWE-345 CWE-672 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-08-18T13:28:28.069Z
Updated: 2026-08-18T18:05:48.847Z
Reserved: 2026-06-04T21:34:34.427Z
Link: CVE-2026-50575
Updated: 2026-08-18T18:05:43.562Z
Status : Received
Published: 2026-08-18T14:17:10.117
Modified: 2026-08-18T18:18:15.247
Link: CVE-2026-50575
No data.