Arbitrary Command Execution in xrdp RDP Server
CVE-2026-33145

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 April 2026

What is CVE-2026-33145?

xrdp is an open source remote desktop protocol server that is being exploited due to unsafe handling of the AlternateShell parameter in its session manager. When the AllowAlternateShell setting is enabled (default configuration), it executes unvalidated client-supplied commands, enabling authenticated users to run arbitrary shell commands. This vulnerability bypasses conventional session initialization restrictions, leading to potential misuse of the server environment in harmful ways. Users are advised to upgrade to version 0.10.6 or later to mitigate this issue.

Affected Version(s)

xrdp < 0.10.6

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.