Improper validation of integrity check value in xrdp - CVE-2026-32105

 

Improper validation of integrity check value in xrdp - CVE-2026-32105

Published: April 17, 2026


Vulnerability identifier: #VU126464
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-32105
CWE-ID: CWE-354
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify encrypted RDP traffic in transit without detection.

The vulnerability exists due to improper validation of integrity check value in the Classic RDP Security layer packet handling when processing encrypted RDP packets. A remote attacker can perform a man-in-the-middle attack to modify encrypted RDP traffic in transit without detection.

It does not affect connections where the TLS security layer is enforced.


Affected software

xrdp
Debian Linux
Fedora
Anolis OS
xrdp (Debian package)
xrdp
xrdp-devel
xrdp-selinux
xrdp-doc

How to mitigate CVE-2026-32105

Install security update from vendor's website.

xrdp - update to 0.10.6
xrdp (Debian package) - update to 0.10.1-3.1+deb13u2
xrdp - update to 0.10.6-1
xrdp-devel - update to 0.10.6-1
xrdp-selinux - update to 0.10.6-1
xrdp-doc - update to 0.10.6-1
xrdp - addressed in versions 0.10.6-1.el8, 0.10.6-1.el9, 0.10.6-1.fc42, 0.10.6-1.fc43, 0.10.6-1.fc44

External References

Related Security Bulletins