
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55626 is a missing authentication vulnerability in xrdp, an open-source RDP server, that allows a local authenticated attacker to bypass session isolation and view or control the active desktop sessions of other users on the same system. It affects xrdp versions 0.10.3 through 0.10.6 when using the Xvnc backend over UNIX domain sockets; users of xorgxrdp or Xvnc over TCP sockets are not affected. The vulnerability was published on July 20, 2026, and patched in version 0.10.6.1 released July 6, 2026. It carries a CVSS v3.1 base score of 7.3 (High) per NVD, and 8.0 (High) per the GitHub Security Advisory (GitHub Advisory, Red Hat).
The root cause is classified as CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function). When xrdp initializes an authenticated user session using the Xvnc backend over UNIX domain sockets, it launches the Xvnc process without enforcing adequate authentication controls, failing to properly isolate the session from other users' active desktop sessions. A local attacker who already has a valid account on the system can exploit this weakness to connect to or interact with another user's Xvnc session running over the UNIX domain socket, effectively hijacking or spying on that session. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows a local authenticated attacker to bypass intended session isolation, enabling unauthorized viewing or control of other users' active desktop sessions on the same system. This results in high confidentiality and integrity impact — an attacker could observe sensitive on-screen data, capture credentials, or manipulate applications running in another user's session. Availability impact is rated low. The vulnerability is scoped to multi-user systems running xrdp with the Xvnc-over-UNIX-domain-socket configuration, and does not enable remote exploitation or direct privilege escalation to root, but could facilitate lateral movement within a shared host environment (GitHub Advisory, Red Hat).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.205%, indicating a low probability of exploitation in the near term. Exploitation requires local authenticated access to the target system, limiting the attacker pool to users with existing accounts (GitHub Advisory, Red Hat).
/tmp or /var/run associated with Xvnc processes (e.g., using ls /tmp/.X*-lock or ps aux | grep Xvnc).vncviewer, xtightvncviewer) running under a user account other than the session owner; processes connecting to UNIX domain sockets belonging to other users' Xvnc sessions./tmp (e.g., .X<display>-unix) by users other than the session owner; unexpected .Xauthority file access patterns./var/log/xrdp.log, /var/log/xrdp-sesman.log) showing session connection events from unexpected user accounts; system audit logs (/var/log/audit/audit.log) recording cross-user socket access events.The primary remediation is to upgrade xrdp to version 0.10.6.1 or later, which was released on July 6, 2026, and addresses this vulnerability along with nine others (xrdp Release). If an immediate upgrade is not possible, administrators should switch to an unaffected backend such as xorgxrdp or configure Xvnc to use TCP sockets instead of UNIX domain sockets. Additionally, restricting local user access to the system and applying the principle of least privilege can reduce the risk of exploitation (GitHub Advisory, Red Hat).
The vulnerability was disclosed via a GitHub Security Advisory by xrdp maintainer metalefty on July 1, 2026, and was part of a batch fix addressing 10 vulnerabilities in the v0.10.6.1 release. Red Hat tracked the issue via Bugzilla and assigned it a high severity rating. Fedora issued updated packages, and the issue received coverage in Linux security news outlets including linuxsecurity.com and pro-linux.de (GitHub Advisory, xrdp Release, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."