Security researchers have released a fully working exploit for a pre-authentication remote code execution (RCE) vulnerability in AnyDesk for Linux, allowing attackers to gain root access before any connection approval is required. The flaw was patched in AnyDesk version 8.0.3 back in June, but the changelog only mentioned "fixed a bug that could lead to a crash"—no CVE was assigned, and no security advisory was issued. This lack of transparency left many users unaware of the severity of the issue until now.
The Vulnerability
The vulnerability resides in the AnyDesk Linux client and can be triggered remotely without authentication. According to the researchers, an attacker can exploit the flaw to execute arbitrary code with root privileges on the target system. This means that even if the AnyDesk service is configured to require user approval for incoming connections, the attacker can bypass that requirement entirely. The pre-auth nature of the flaw makes it particularly dangerous, as it can be exploited without any user interaction or credentials.
Patch and Disclosure Timeline
AnyDesk addressed the issue in version 8.0.3, released in June 2026. However, the company's changelog described the fix only as a crash bug, omitting any mention of a security vulnerability. No CVE identifier was requested, and no advisory was published. This low-profile patching approach is not uncommon, but it can leave organizations unaware of the need to update urgently. The researchers who discovered the flaw have now published a detailed exploit, raising concerns about active exploitation.
Technical Details
While the exact technical details of the exploit are not fully disclosed in the source, the researchers have demonstrated a working proof-of-concept that achieves remote code execution as root. The attack vector likely involves a memory corruption issue in the AnyDesk service that can be triggered by sending a specially crafted packet. Because the flaw is pre-authentication, the attacker does not need to know any credentials or have any prior access to the system. The exploit is reliable and can be used to compromise Linux systems running vulnerable versions of AnyDesk.
Impact and Mitigation
Any Linux system running AnyDesk versions prior to 8.0.3 is potentially vulnerable. This includes servers, workstations, and any other Linux-based devices with the AnyDesk service installed and running. Given that AnyDesk is widely used for remote administration, the impact could be significant, especially in enterprise environments where Linux servers are common.
To mitigate the risk, users and administrators should immediately upgrade to AnyDesk 8.0.3 or later. If immediate upgrading is not possible, consider disabling the AnyDesk service or restricting network access to trusted IP addresses. Additionally, monitor for any suspicious activity related to AnyDesk, such as unexpected connections or process executions.
The Importance of Transparent Disclosure
This incident highlights the ongoing challenge of silent patching. When vendors fix security vulnerabilities without assigning a CVE or publishing an advisory, it hinders the ability of defenders to prioritize patching and assess risk. It also delays the broader security community's understanding of active threats. While AnyDesk may have had reasons for the low-key approach, the publication of the exploit underscores the need for more transparent communication.
Conclusion
The release of a working exploit for the AnyDesk Linux pre-auth RCE flaw is a stark reminder of the importance of prompt patching and vendor transparency. Organizations should verify their AnyDesk versions and update immediately. As remote access tools remain a prime target for attackers, staying informed about vulnerabilities and applying patches swiftly is critical to maintaining a secure environment.
For more details, refer to the original report: Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access