Vulnerability
Published 2026-10-08
Verified 2026-10-09

AnyDesk for Linux 'AnyPwn': working exploit published for a pre-authentication heap overflow that runs commands as root before anyone accepts the connection; fixed quietly in 8.0.3 (June), no CVE or advisory

Researchers from the V12 security team (Rick de Jager) published a full working exploit on GitHub on 8 October 2026 for a heap buffer overflow in the session protocol of AnyDesk for Linux. When handling mode-5 stream packets, AnyDesk adds a 16-byte header to the payload length declared by the remote side using 32-bit arithmetic with no overflow check; a declared length of 0xFFFFFFF0 wraps to a tiny allocation while the object keeps the huge length, so attacker data is written past the end of the buffer. Because the AnyDesk service normally runs as root on Linux, the exploit gains root command execution before the desktop user approves the session. The published exploit works over direct TCP connections to port 7070 and is tuned for build 8.0.2; it is probabilistic and may crash the service instead. The researchers say the same code path is reachable through AnyDesk relay servers (shown only with a minimal trigger), while AnyDesk said in June that the issue is limited to direct connections on Linux and that Windows and macOS are not affected. The researchers reported the bug on 22 June; AnyDesk fixed it in Linux 8.0.3 the next day with a changelog line about a crash, assigned no CVE and issued no advisory (none as of 9 October). The latest Linux release is 8.1.0. No exploitation in the wild has been reported. Source: V12's research release on GitHub; wire: The Hacker News.

Product
AnyDesk for Linux — session protocol (mode-5 stream packets), service mode
Versions
8.0.2 confirmed exploitable (exploit offsets target this build); earlier builds such as 8.0.1 may share the code path. Windows and macOS not affected per AnyDesk.
Exploited in Australia?
unknown
Patch to
Update AnyDesk for Linux to 8.0.3 or later (latest 8.1.0). If you cannot update at once, block inbound TCP 7070 to Linux hosts running AnyDesk and remove AnyDesk from servers that do not need it.

Primary: The Hacker News — Researchers publish working exploit for pre-auth AnyDesk Linux flaw that gives root access (9 Oct 2026; V12 code released on GitHub 8 Oct) · Vendor: AnyDesk — Linux changelog (8.0.3 fix; latest 8.1.0) · V12 security team — AnyPwn research (Rick de Jager)

vulnerabilities network