Path Traversal Vulnerability in FreeRDP Before Version 3.29.0
CVE-2026-67295

5.3MEDIUM

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67295?

A vulnerability exists in FreeRDP prior to version 3.29.0, where the software does not adequately validate server-supplied RDPDR paths during drive redirection. This flaw allows attackers to access sibling paths outside the designated shared root directory. By exploiting this vulnerability, a malicious RDP server could potentially read, write, delete, and enumerate files in sibling directories through the use of non-rooted paths that bypass the shared-root boundary checks.

Affected Version(s)

FreeRDP 0 < 3.29.0

FreeRDP 3.29.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

1121984919
.