Parsing Vulnerability in xrdp Open Source RDP Server Affects Security Features
CVE-2026-55639

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-55639?

xrdp, an open-source Remote Desktop Protocol (RDP) server, has a vulnerability that occurs during the parsing of Client Security Data in the Client MCS Connect Initial PDU. This flaw exists due to insufficient length validation of incoming data during the initial connection sequence, specifically within the capability and security negotiation phase. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted RDP packet with malformed data. The inadequacies in bounds checking may enable the xrdp process to read beyond the designated boundaries of the data block, leading to potential disclosure of sensitive process memory. This issue has been addressed in version 0.10.6.1, and users are advised to upgrade to mitigate risk.

Affected Version(s)

xrdp < 0.10.6.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.