Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On October 9, 2026, researchers published the full AnyPwn exploit code, a pre-authentication exploit for AnyDesk Linux that achieves remote code execution with root privileges. The release makes practical an attack theorized in June, when AnyDesk shipped version 8.0.3 with a minimal description of the issue. The vendor never assigned a CVE or issued a formal security advisory, leaving administrators without guidance on the flaw's true severity.
- The AnyPwn exploit enables root RCE on AnyDesk Linux without requiring connection approval
- The bug was silently fixed in AnyDesk 8.0.3 in June 2026, but the changelog described only a potential crash
- The exploit is probabilistic: it depends on the heap layout of the target 8.0.2 build, with specific offsets requiring recalibration for other versions
- No CVE has been assigned and no formal security advisory published by AnyDesk as of October 9, 2026
The Mechanism: From Integer Overflow to Heap Corruption
The vulnerability resides in the AnyDesk session protocol, specifically in so-called mode-5 stream packets. The memory allocation size calculation uses 32-bit arithmetic without an overflow check: the code adds 16 bytes of header to the payload length, both in an unsigned 32-bit integer. When the declared payload is 0xFFFFFFF0, adding 0x10 wraps to zero, allocating a minimal buffer while the system records the original length.
Every byte the attacker writes then exceeds the allocated buffer boundaries, triggering a heap buffer overflow. This corruption of adjacent objects in the heap layout enables construction of a ROP chain for arbitrary command execution with root privileges. The AnyDesk service on Linux runs with elevated permissions, making full system compromise the natural outcome of a successful exploit.
The published exploit is, however, probabilistic: success depends on the presence of a target object adjacent to the corrupted buffer in the specific process heap layout. If this condition is not met, the service crashes. Offsets in the released code are calibrated for the specific AnyDesk Linux 8.0.2 build; other builds require manual recalibration.
Timeline of Silence: June to October Without a CVE
The vulnerability was discovered by Rick de Jager of the V12 security team, who used the V12 code review engine to identify the vulnerable path. On June 22, 2026, researchers publicly disclosed the flaw; AnyDesk responded the next day by releasing version 8.0.3. That version's changelog described the fix as "fixed a bug that could lead to a crash."
"fixed a bug that could lead to a crash" — AnyDesk changelog, version 8.0.3 (June 2026)
The wording downplayed the pre-authentication nature of the exploit and omitted any reference to RCE or root privileges. As of October 9, 2026, four months later, no CVE has been assigned to the vulnerability and no formal security advisory has been published. Researchers noted that the 8.0.2 build disappeared from the download page while remaining visible in the changelog; they commented that the vendor "appears to have deleted (?) the 8.0.2 build" coinciding with the release of their proof-of-concept video.
Attack Surface: Direct, Not Relay
In June, AnyDesk stated the vulnerability is "limited to direct connections on Linux (connections that do not go through our relays)" and that "Windows and macOS are not affected." The published exploit works exclusively on direct TCP connections on port 7070, a subset of AnyDesk connection modes.
Researchers have, however, validated with Frida instrumentation that the same vulnerable path is reachable via AnyDesk relay servers, though they have not demonstrated full exploit chain completeness in that configuration. This element remains unverified in practice: the bug trigger is confirmed, but RCE via relay has not been proven with the released code.
The exploit explicitly targets version 8.0.2. Researchers imply earlier versions such as 8.0.1 may share the vulnerable path, but have not confirmed exploitation on those builds. AnyDesk Linux 8.1.0 is the latest version available at the time of reporting.
Why It Matters
The case documents a systemic discrepancy between the technical severity of a vulnerability and its public representation by the vendor. A pre-auth root RCE was described as a potential crash; the fix was distributed without a CVE, without an advisory, without priority guidance for updates. This disclosure model leaves system administrators without the tools to assess risk: patch management depends on perceived criticality, and that perception was deliberately dampened.
The absence of a CVE also prevented automatic ingestion into vulnerability management platforms, potentially delaying coverage in organizations reliant on those feeds. The removal of the vulnerable build from the download page, if confirmed as intentional, constitutes a form of opaque response that does not substitute for informational transparency.
The brief does not specify additional remediation measures recommended by AnyDesk or the researchers, nor does it document whether configurations exist that limit exposure of port 7070 or isolate the service from the external network interface. The source does not clarify whether the exploit has been reproduced on installations with compilation customizations differing from the standard 8.0.2 build.
For the industry, the episode raises questions about disclosure responsibilities: when a vendor patches a critical flaw without adequately documenting it, exploit publication becomes the only mechanism to force risk visibility, with the collateral cost of arming attackers.
Sources
- https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html
- https://www.securityweek.com/cisco-patches-a-dozen-critical-vulnerabilities/
- https://www.securityweek.com/citrix-urges-immediate-patching-of-critical-netscaler-vulnerability/
- https://blog.netmanageit.com/researchers-publish-working-exploit-for-pre-auth-anydesk-linux-flaw-that-gives-root-access/
- https://www.guardianmssp.com/2026/10/09/researchers-publish-working-exploit-for-pre-auth-anydesk-linux-flaw-that-gives-root-access/
- https://www.theregister.com/security/2026/06/29/anonymous-researcher-drops-0-day-exploitarium-repo/5263961
- https://nvd.nist.gov/vuln/detail/CVE-2026-58053
- https://sec.cloudapps.cisco.com/security/center/publicationListing.x
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-fBn58ELx
- https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html
Information is based on cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.