---
cve: "CVE-2026-79680"
severity: "MEDIUM"
cvss: 4.5
epss: ""
vendor: "Qt"
kev: false
exploited: false
published: "2026-09-24 11:16:47"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-28T08:15:03+02:00"
---

# CVE-2026-79680

> 4.5 MEDIUM

## Beschreibung

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the confidentiality and integrity of the session.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/V:D/RE:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |

## BSI-Hinweise (deutsch)

- [QT: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3586) — _BSI-Einstufung: hoch_
  Ein entfernter, anonymer Angreifer kann eine Schwachstelle in QT ausnutzen, um Sicherheitsvorkehrungen zu umgehen.

## Referenzen

- <https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-79680:>
- <https://codereview.qt-project.org/c/qt/tqtc-qtvncserver/+/759160>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-79680) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
