PT-2026-33505 · Xrdp · Xrdp
Smittix
·
Published
2026-04-17
·
Updated
2026-05-19
·
CVE-2026-33145
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
xrdp versions prior to 0.10.6
Description
An authenticated remote user can execute arbitrary commands on the server due to unsafe handling of the
AlternateShell parameter in xrdp-sesman. When the AllowAlternateShell setting is enabled, the server accepts a client-supplied AlternateShell value and executes it via /bin/sh -c during session initialization. This leads to shell-interpreted execution of unsanitized, user-controlled input, providing a remote command execution primitive within the security context of the authenticated user before the window manager starts. This process can bypass session initialization flows that normally restrict execution to interactive desktop environments.Recommendations
Update to version 0.10.6.
As a temporary workaround, disable the
AllowAlternateShell setting to prevent the execution of client-supplied shell values.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xrdp