Path Traversal Vulnerability in FreeRDP Before Version 3.29.0
CVE-2026-67295
5.3MEDIUM
What is CVE-2026-67295?
A vulnerability exists in FreeRDP prior to version 3.29.0, where the software does not adequately validate server-supplied RDPDR paths during drive redirection. This flaw allows attackers to access sibling paths outside the designated shared root directory. By exploiting this vulnerability, a malicious RDP server could potentially read, write, delete, and enumerate files in sibling directories through the use of non-rooted paths that bypass the shared-root boundary checks.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
