CVE Explorer
CVE-2026-55626
xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them to unauthorizedly view or control the active desktop sessions of other users on the same system. Users using other backends, such as xorgxrdp or X
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6420bad623cfa57782664e4fc7b163cab9cfae0c7cf1b841d09b8d24f684b5f1 · sha256:0b9c113f2672806c… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-287","description":"CWE-287: Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6420bad623cfa57782664e4fc7b163cab9cfae0c7cf1b841d09b8d24f684b5f1 · sha256:0b9c113f2672806c… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"xrdp","vendor":"neutrinolabs","versions":[{"status":"affected","version":"< 0.10.6.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6420bad623cfa57782664e4fc7b163cab9cfae0c7cf1b841d09b8d24f684b5f1 · sha256:0b9c113f2672806c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6420bad623cfa57782664e4fc7b163cab9cfae0c7cf1b841d09b8d24f684b5f1 · sha256:0b9c113f2672806c… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6420bad623cfa57782664e4fc7b163cab9cfae0c7cf1b841d09b8d24f684b5f1 · sha256:0b9c113f2672806c… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-287","description":"CWE-287: Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6420bad623cfa57782664e4fc7b163cab9cfae0c7cf1b841d09b8d24f684b5f1 · sha256:0b9c113f2672806c… · /containers/cna/problemTypes/1/descriptions/0
Source references
2 source assertions{"name":"https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1","tags":["x_refsource_MISC"],"url":"https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6420bad623cfa57782664e4fc7b163cab9cfae0c7cf1b841d09b8d24f684b5f1 · sha256:0b9c113f2672806c… · /containers/cna/references/1
{"name":"https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-m3xx-cpc4-982r","tags":["x_refsource_CONFIRM"],"url":"https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-m3xx-cpc4-982r"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6420bad623cfa57782664e4fc7b163cab9cfae0c7cf1b841d09b8d24f684b5f1 · sha256:0b9c113f2672806c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.