Junglewise Threat Intelligence

CVE-2026-55626: neutrinolabs xrdp improper authentication in Xvnc backend

CVE-2026-55626 · Severity: high · CVSS 8 · Published 2026-07-20

Technologies: Neutrinolabs Xrdp. Vendors: Neutrinolabs.

Executive brief

xrdp is an open-source tool that allows users to remotely access a computer's desktop. A security flaw in certain versions allows a person already logged into the system to bypass security boundaries and view or control the active desktop sessions of other users. This could lead to the theft of sensitive information or unauthorized actions being taken in another user's name.

Technical details

A vulnerability exists in xrdp versions 0.10.3 through 0.10.6 due to improper authentication when initializing Xvnc backends over UNIX domain sockets (UDS). When a session is started in this specific configuration, the Xvnc process is launched without sufficient authentication checks, failing to enforce proper session isolation. A local authenticated attacker can exploit this to connect to and intercept or control the desktop sessions of other users on the same host. The vulnerability is specific to the UDS transport; users utilizing xorgxrdp or Xvnc over TCP sockets are not affected. The issue is addressed in version 0.10.6.1 by implementing proper authentication for UDS-based Xvnc sessions.

Affected products

  • neutrinolabs xrdp 0.10.3 - 0.10.6

Timeline

  • 2026-07-01: advisory: Initial GitHub security advisory published
  • 2026-07-06: patched: Version 0.10.6.1 released
  • 2026-07-20: disclosed: CVE-2026-55626 published to NVD

References

Related threats