Remote Desktop Protocol Vulnerability in FreeRDP Affects Unauthorized Client Authentication
CVE-2026-73241

8.3HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73241?

FreeRDP is a widely used open-source implementation of the Remote Desktop Protocol. In versions prior to 3.30.0, a vulnerability exists in the server-side RDSTLS component. The issue arises when the system accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES Protocol Data Unit (PDU) while it is supposed to be waiting for the RDSTLS_TYPE_AUTHREQ. This situation leaves the resultCode set to RDSTLS_RESULT_SUCCESS, which can be exploited by remote, unauthenticated clients to bypass critical authentication checks, including the RedirectionGuid, username, domain, and password requirements. The vulnerability has been addressed in version 3.30.0.

Affected Version(s)

FreeRDP < 3.30.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.