Observable Response Discrepancy in xrdp - CVE-2026-42218
Published: June 15, 2026
xrdp
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information via username enumeration.
The vulnerability exists due to observable response discrepancy in the login interface when processing authentication attempts. A remote attacker can measure response timing differences to disclose sensitive information via username enumeration.