AnyDesk Linux pre-auth RCE flaw (published exploit)
Vulnerability
Summary
Hide ▲
Show ▼
A working exploit is now public for an AnyDesk Linux pre-authentication remote code execution flaw, exposing systems to root access before connection approval. AnyDesk fixed the issue in version 8.0.3 in June, but the flaw still had no CVE as of October 9. The published code targets direct TCP connections on port 7070 and shows that the bug can be weaponized even before a session is accepted. Relay-based exploitation remains unresolved.
Timeline
-
09.10.2026 15:59 1 articles · 4h ago
Researchers disclose a pre-authentication AnyDesk Linux root RCE flaw
Initial DisclosureSecurity researchers disclosed a pre-authentication remote code execution flaw in AnyDesk Linux that can give an attacker root access before a connection is approved.
Show sources
- Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access — thehackernews.com — 09.10.2026 15:59
-
09.10.2026 15:59 1 articles · 4h ago
AnyDesk releases version 8.0.3 to fix the Linux flaw
Mitigation Patch UpdateAnyDesk released version 8.0.3 for AnyDesk Linux to address the vulnerability after acknowledging it, while describing the change only as a crash fix and not issuing a CVE or security advisory.
Show sources
- Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access — thehackernews.com — 09.10.2026 15:59
-
09.10.2026 15:59 2 articles · 4h ago
AnyPwn exploit code is released on GitHub
Technical Analysis UpdateResearchers released AnyPwn on GitHub, publishing a working exploit for the heap buffer overflow in AnyDesk's session protocol that targets AnyDesk Linux 8.0.2 and can execute commands as root over direct TCP connections on port 7070.
Show sources
- Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access — thehackernews.com — 09.10.2026 15:59
- Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access — thehackernews.com — 09.10.2026 15:59
-
09.10.2026 03:00 1 articles · 17h ago
AnyDesk Linux flaw remains without a CVE or formal advisory
Untyped PhaseAs of October 9, the AnyDesk Linux vulnerability still had no CVE and no formal security advisory, and the researchers said the published exploit worked only over direct TCP connections on port 7070 while relay-based full exploitation remained unresolved.
Show sources
- Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access — thehackernews.com — 09.10.2026 15:59