---
id: CVE-2026-79680
title: >-
  Authentication bypass vulnerability in the password authentication mechanism
  of the Qt VNC Server module
summary: >-
  Authentication bypass vulnerability in the password authentication mechanism
  of the Qt VNC Server module. An attacker using a specially modified VNC client
  that violates the RFB protocol can bypass Qt VNC Server's password
  authentication…
severity: medium
cvss: 4.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/V:D/RE:L'
cwe:
  - CWE-288
vendor: qt
product: qt
affected:
  - qt >= 6.4.0 < 6.8.9
  - qt >= 6.9.0 < 6.11.3
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T13:17:11.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79680'
references:
  - url: 'https://codereview.qt-project.org/c/qt/tqtc-qtvncserver/+/759160'
    label: a59d8014-47c4-4630-ab43-e1b13cbe58e3
  - url: >-
      https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-79680:
    label: a59d8014-47c4-4630-ab43-e1b13cbe58e3
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T12:17:35.115651Z'
cvssSource: cna
ingestedAt: '2026-09-24T11:42:06.844Z'
---

## Overview

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the confidentiality and integrity of the session.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
