Authentication Bypass in xrdp Affects Open Source RDP Server
CVE-2026-55626

8HIGH

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-55626?

The xrdp software, an open-source Remote Desktop Protocol (RDP) server, is susceptible to an authentication bypass issue. The vulnerability emerges when an authenticated user session is started using the Xvnc backend via UNIX domain sockets. This implementation lacks sufficient authentication, potentially enabling a local authenticated attacker to gain unauthorized access to the desktop sessions of other users on the same system. Users who utilize alternative backends, such as xorgxrdp or Xvnc over TCP, remain unaffected. The issue has been resolved in the xrdp version 0.10.6.1 release.

Affected Version(s)

xrdp < 0.10.6.1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.