TLS Certificate Identity Validation Weakness in FreeRDP by FreeRDP
CVE-2026-66402

9.3CRITICAL

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-66402?

FreeRDP, prior to version 3.29.0, contains multiple vulnerabilities in its TLS certificate identity validation procedures. Specifically, it uses custom methods for matching Common Names and DNS Subject Alternative Names (SANs), which expose several security flaws. These issues include truncating DNS SAN values at embedded NUL bytes, incorrectly accepting a Common Name despite the presence of non-matching DNS SAN entries, and allowing IP-literal targets without proper comparison to iPAddress SANs. Consequently, attackers with an ability to present a trusted or misissued certificate can potentially bypass server identity verification, leading to significant risks in TLS server authentication.

Affected Version(s)

FreeRDP 0 < 3.29.0

FreeRDP 3.29.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

1121984919
.