PT-2026-61024 · Xrdp · Xrdp

CVE-2026-55626

·

Published

2026-07-08

·

Updated

2026-07-21

CVSS v3.1

8.0

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6.1
Description An issue exists when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, as the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker can exploit this to bypass session isolation and unauthorizedly view or control active desktop sessions of other users on the same system. This does not affect users of other backends, such as xorgxrdp, or those using Xvnc over TCP sockets.
Recommendations Update to version 0.10.6.1. As a temporary mitigation, avoid using the Xvnc backend over UNIX domain sockets.

Exploit

Fix

LPE

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55626
GHSA-M3XX-CPC4-982R

Affected Products

Xrdp