Description
AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.
Published: 2026-07-13
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability involves the Send Support arbitrary files. By abusing this path‑resolution bug (CWE‑59), the attacker can cause the application or the underlying system to enter a denial‑of‑service state. The impact is a local denial of service; it does not provide elevated privileges or remote code execution.

Affected Systems

AnyDesk, version information not specified in the advisory. The flaw exists in AnyDesk installations that include the Send Support Information functionality. All users running AnyDesk should evaluate whether they have used that feature.

Risk and Exploitability

The CVSS score of 4.7 reflects a moderate impact, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The vulnerability requires local access and low‑privileged execution, so the exploit requires the system with limited privileges. No exploits are reported in the wild, and there is no indication that the flaw is actively exploited. However, because the flaw can lead to a DoS condition, organizations should treat it as a moderate risk, especially in environments where AnyDesk features are used frequently.

Generated by OpenCVE AI on July 31, 2026 at 11:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest AnyDesk update that addresses this path‑resolution bug.
  • If a patch is not yet available, disable the Send Support Information feature or restrict its use to a trusted user group, thereby preventing users from creating junctions that could be abused.
  • Review and tighten file‑system permissions to ensure that local users cannot create junctions in directories that are used by the AnyDesk support service, and consider monitoring for unexpected junction creation.

Generated by OpenCVE AI on July 31, 2026 at 11:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Anydesk
Anydesk anydesk
Vendors & Products Anydesk
Anydesk anydesk

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.
Title AnyDesk Support Information Link Following Denial-of-Service Vulnerability
Weaknesses CWE-59
References
Metrics cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-07-14T12:51:30.078Z

Reserved: 2026-07-13T21:29:24.642Z

Link: CVE-2026-15682

cve-icon Vulnrichment

Updated: 2026-07-14T12:51:26.389Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:15:05Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')