Missing Authentication for Critical Function in xrdp - CVE-2026-55626

 

Missing Authentication for Critical Function in xrdp - CVE-2026-55626

Published: July 1, 2026


Vulnerability identifier: #VU136616
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55626
CWE-ID: CWE-306
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to view or control other users' active desktop sessions.

The vulnerability exists due to improper authentication in the Xvnc backend when initializing an authenticated user session over UNIX domain sockets. A remote attacker can connect to the insufficiently protected Xvnc process to view or control other users' active desktop sessions.

Only systems using the Xvnc backend over UNIX domain sockets are affected; deployments using xorgxrdp or Xvnc over TCP sockets are not affected.


Affected software

xrdp
Fedora
xrdp

How to mitigate CVE-2026-55626

Install security update from vendor's website.

xrdp - update to 0.10.6.1
xrdp - addressed in versions 0.10.6.1-1.el8, 0.10.6.1-1.el9, 0.10.6.1-1.fc43, 0.10.6.1-1.fc44

External References

Related Security Bulletins