Arbitrary Command Execution in xrdp RDP Server
CVE-2026-33145
6.3MEDIUM
What is CVE-2026-33145?
xrdp is an open source remote desktop protocol server that is being exploited due to unsafe handling of the AlternateShell parameter in its session manager. When the AllowAlternateShell setting is enabled (default configuration), it executes unvalidated client-supplied commands, enabling authenticated users to run arbitrary shell commands. This vulnerability bypasses conventional session initialization restrictions, leading to potential misuse of the server environment in harmful ways. Users are advised to upgrade to version 0.10.6 or later to mitigate this issue.
Affected Version(s)
xrdp < 0.10.6
