Description
Rocket Software Rocket Remote Desktop 18.0.8583.1 is vulnerable to Insufficiently Protected Credentials.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Compromised Authentication
Action: Patch ASAP
AI Analysis

Impact

Rocket Software Rocket Remote Desktop version 18.0.8583.1 contains insufficiently protected credentials, meaning user login information may be stored or transmitted without adequate safeguards. This weakness allows an attacker who obtains or guesses valid credentials to gain unauthorized access, potentially escalating to system control and exposing sensitive data. The impact is primarily the loss of confidentiality and integrity for users and any information accessed through the remote desktop session.

Affected Systems

The affected vendor is Rocket Software, with the product Rocket Remote Desktop. The vulnerability applies to the 18.0.8583.1 build; other releases are not confirmed as vulnerable.

Risk and Exploitability

The CVSS score is not published, and the EPSS indicates no data, so exact exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV. Attackers could remotely target the authentication mechanism, infer or brute‑force credentials, and then log into the remote desktop service. No known work‑arounds are provided by the vendor, so the primary risk is exploitation of exposed plaintext or weakly encrypted credentials.

Generated by OpenCVE AI on October 9, 2026 at 20:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Rocket Remote Desktop to the latest release that addresses credential protection.
  • Reconfigure credential storage to use strong hashing or encryption; avoid storing passwords in plaintext or reversible formats.
  • If an upgrade is delayed, enforce tight network segmentation, restrict remote access to trusted hosts, and ensure all accounts use complex, unique passwords.

Generated by OpenCVE AI on October 9, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Title Insufficiently Protected Credentials in Rocket Remote Desktop 18.0.8583.1
Weaknesses CWE-256

Fri, 09 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Rocket Software Rocket Remote Desktop 18.0.8583.1 is vulnerable to Insufficiently Protected Credentials.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-09T18:39:30.454Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-78835

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T19:16:42.420

Modified: 2026-10-09T19:16:42.420

Link: CVE-2026-78835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T20:30:11Z

Weaknesses
  • CWE-256

    Plaintext Storage of a Password