PT-2026-61024 · Xrdp · Xrdp
CVE-2026-55626
·
Published
2026-07-08
·
Updated
2026-07-21
CVSS v3.1
8.0
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
xrdp versions prior to 0.10.6.1
Description
An issue exists when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, as the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker can exploit this to bypass session isolation and unauthorizedly view or control active desktop sessions of other users on the same system. This does not affect users of other backends, such as xorgxrdp, or those using Xvnc over TCP sockets.
Recommendations
Update to version 0.10.6.1.
As a temporary mitigation, avoid using the Xvnc backend over UNIX domain sockets.
Exploit
Fix
LPE
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xrdp