PT-2026-67274 · Freerdp · Freerdp

·

CVE-2026-67294

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.29.0
Description Improper validation of the Extended Key Usage (EKU) purpose occurs during client-side server TLS authentication. Within the x509 utils verify() function, if the server-purpose (X509 PURPOSE SSL SERVER) verification fails, the system incorrectly falls back to client-purpose and any-purpose verification. This allows a trusted certificate that matches the hostname but is only valid for client authentication to be accepted as a legitimate RDP server certificate, bypassing purpose validation in environments that separate client and server certificate roles.
Recommendations Update to version 3.29.0 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67294
GHSA-89C6-JJRW-96H4

Affected Products

Freerdp