CVE-2026-50575 PUBLISHED

BetterDesk has a replay behavior vulnerability when devices are deleted

Assigner: GitHub_M
Reserved: 04.06.2026 Published: 18.08.2026 Updated: 18.08.2026

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
CVSS Score: 7.7

Product Status

Vendor UNITRONIX
Product BetterDesk
Versions
  • Version < 3.0.0-alpha is affected

References

Problem Types

  • CWE-294: Authentication Bypass by Capture-replay CWE
  • CWE-345: Insufficient Verification of Data Authenticity CWE
  • CWE-672: Operation on a Resource after Expiration or Release CWE