CVE-2026-15682

anydesk: Improper Link Resolution Before File Access ('Link Following') (CVE-2026-15682)

mediumEPSS 0.1%

Description

AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

anydeskanydesk

Metrics

5.5
Source: nvd-v3
3.0 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-13 21:31 UTC
CWE-59

Weakness classes (CWE)

  • CWE-59Base

    Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

    cwe.mitre.org →

References & sources