Skip to content
qt-group-plcCVE-2026-79680

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module.

Medium4.5CVE-2026-79680 · Published Sep 24, 2026

Source advisory

Affected versions

PackageAffectedFixed in
qt
Vendor
>= 6.4.0, < 6.8.96.8.9
>= 6.9.0, < 6.11.36.11.3
Details and references

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the confidentiality and integrity of the session.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:X
Severity from
no source yet
Weakness
CWE-288

More qt-group-plc advisories

All

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.