CVE-2026-55626

neutrinolabs · xrdp

A missing authentication vulnerability in the xrdp server allows attackers to bypass security controls for critical functions.

Executive summary

The xrdp server contains a critical authentication bypass vulnerability that allows unauthenticated local attackers to gain unauthorized access to the system.

Vulnerability

The software fails to perform necessary authentication checks for critical functions. The CVSS vector (AV:L/PR:N/UI:N) indicates that an attacker with local access can exploit this without prior authentication.

Business impact

Exploitation of this vulnerability allows for complete unauthorized access to the affected system, potentially leading to full system compromise. With a CVSS score of 8.0, this represents a major security risk for any environment relying on xrdp for remote desktop connectivity.

Remediation

Immediate Action: Update the xrdp package to version 0.10.6.1 or later immediately.

Proactive Monitoring: Review system authentication logs for unusual login patterns or sessions created without standard authentication handshakes.

Compensating Controls: Disable the xrdp service if it is not strictly required for business operations, or apply strict local firewall rules to restrict access to the xrdp port.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The risk of unauthorized access is severe, and the lack of authentication requirements makes this an attractive target for local attackers. System administrators must prioritize upgrading to the patched version of xrdp to eliminate this vulnerability.