Missing Authentication for Critical Function in xrdp - CVE-2026-55626
Published: July 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to view or control other users' active desktop sessions.
The vulnerability exists due to improper authentication in the Xvnc backend when initializing an authenticated user session over UNIX domain sockets. A remote attacker can connect to the insufficiently protected Xvnc process to view or control other users' active desktop sessions.
Only systems using the Xvnc backend over UNIX domain sockets are affected; deployments using xorgxrdp or Xvnc over TCP sockets are not affected.
Affected software
Fedora
xrdp
How to mitigate CVE-2026-55626
xrdp - addressed in versions 0.10.6.1-1.el8, 0.10.6.1-1.el9, 0.10.6.1-1.fc43, 0.10.6.1-1.fc44