
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33689 is an out-of-bounds read vulnerability in xrdp, an open-source RDP server, affecting all versions through 0.10.5. The flaw resides in the pre-authentication RDP message parsing logic, specifically in the dynamic channel communication handler, and can be triggered by a remote, unauthenticated attacker during the initial connection phase. It was published on April 17, 2026, and fixed in xrdp version 0.10.6 released the same day. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-125 (Out-of-bounds Read): the xrdp dynamic channel parser fails to adequately validate input buffer lengths before reading data during the pre-authentication phase of the RDP handshake. An unauthenticated attacker can send a specially crafted sequence of RDP packets during the initial connection phase to trigger the out-of-bounds read without any prior authentication or user interaction. No special privileges or network positioning are required — the service is typically exposed on TCP port 3389. The vulnerability was credited to researchers @exploitintel, @smittix, and @hessandrew (GitHub Advisory, xrdp v0.10.6 Release).
Successful exploitation can result in two primary outcomes: a denial-of-service (DoS) condition caused by a process crash of the xrdp service, and potential disclosure of sensitive information from the service's memory space. Because the flaw is triggered pre-authentication, any internet-exposed xrdp instance is at risk without any user interaction or credential requirement. Integrity is not directly impacted, but memory disclosure could expose credentials, session tokens, or other sensitive data processed by the RDP server (GitHub Advisory, Red Hat Bugzilla).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.243%, indicating a low current probability of exploitation in the wild. However, the network-accessible, pre-authentication nature of the flaw with no complexity requirements makes it an attractive target for future weaponization. The vulnerability is detectable via Nessus plugin 307460 (Tenable).
/var/log/xrdp.log) showing repeated connection errors, parsing failures, or segmentation faults during the pre-authentication phase; entries referencing dynamic channel processing errors.xrdp process (observable via systemd journal: journalctl -u xrdp); core dump files generated in the xrdp working directory.core.*) in /var/run/xrdp/ or the xrdp installation directory following service crashes.The primary remediation is to upgrade xrdp to version 0.10.6 or later, which was released on April 17, 2026, and contains fixes for CVE-2026-33689 along with several other security issues (xrdp v0.10.6 Release). As a temporary workaround where patching is not immediately possible, administrators should restrict access to TCP port 3389 using firewall rules, limiting connections to trusted IP ranges only. Additionally, placing xrdp behind a VPN or network access control layer reduces the attack surface by preventing unauthenticated external access. Fedora and openSUSE package updates incorporating the fix have also been released (Linux Security Fedora, openSUSE Security).
The vulnerability was reported by security researchers @exploitintel, @smittix, and @hessandrew, who were credited in the xrdp v0.10.6 release notes (xrdp v0.10.6 Release). Red Hat tracked the issue via Bugzilla and assigned it high priority and severity (Red Hat Bugzilla). Coverage appeared on Linux security news outlets including pro-linux.de and linuxsecurity.com following the Fedora and openSUSE package updates. Social media activity was limited, with automated CVE notification accounts on Bluesky and Nitter posting about the disclosure shortly after publication.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."