Command injection in xrdp - CVE-2026-33145

 

Command injection in xrdp - CVE-2026-33145

Published: April 17, 2026


Vulnerability identifier: #VU126460
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33145
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands on the server.

The vulnerability exists due to command injection in xrdp-sesman when processing a client-supplied AlternateShell value during session initialization. A remote user can supply a crafted AlternateShell value to execute arbitrary commands on the server.

The issue occurs when the AllowAlternateShell setting is enabled, which is the default if not explicitly configured, and command execution happens prior to normal window manager startup.


Affected software

xrdp
Debian Linux
Fedora
xrdp (Debian package)
xrdp

How to mitigate CVE-2026-33145

Install security update from vendor's website.

xrdp - update to 0.10.6
xrdp (Debian package) - update to 0.10.1-3.1+deb13u2
xrdp - addressed in versions 0.10.6-1.el8, 0.10.6-1.el9, 0.10.6-1.fc42, 0.10.6-1.fc43, 0.10.6-1.fc44

External References

Related Security Bulletins