CVE-2026-55626
xrdp vulnerability analysis and mitigation

Overview

CVE-2026-55626 is a missing authentication vulnerability in xrdp that allows local authenticated attackers to bypass session isolation and access or control other users' active desktop sessions. It affects xrdp versions 0.10.3 through 0.10.6 when using the Xvnc backend over UNIX domain sockets. The vulnerability was published on July 1, 2026, and a patched version (0.10.6.1) has been released. It carries a CVSS v3.1 base score of 8.0 (High) (GitHub Advisory).

Technical details

The root cause is insufficient authentication when xrdp launches the Xvnc process in UNIX domain socket mode during session initialization. When an authenticated user session is set up via the Xvnc backend over UNIX domain sockets, the spawned Xvnc process lacks adequate authentication controls, enabling a local attacker to connect to another user's Xvnc session without authorization. This is classified as a missing authentication for critical function issue. Notably, deployments using other backends — such as xorgxrdp or Xvnc over TCP sockets — are not affected by this vulnerability (GitHub Advisory).

Impact

A local authenticated attacker who successfully exploits this vulnerability can view or control the active desktop sessions of other users on the same system, resulting in high confidentiality and integrity impact and low availability impact. This could expose sensitive data visible on other users' desktops, allow unauthorized input injection into their sessions, and facilitate privilege escalation or lateral movement within a multi-user environment (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target multi-user Linux system running xrdp versions 0.10.3–0.10.6 configured to use the Xvnc backend over UNIX domain sockets.
  2. Obtain local access: Authenticate to the system as any local user (no elevated privileges required).
  3. Identify active Xvnc sessions: Enumerate UNIX domain sockets on the system (e.g., using ss -x or inspecting /tmp/.X11-unix/) to locate Xvnc sockets associated with other users' xrdp sessions.
  4. Connect to target session: Use a VNC client or tool capable of connecting over UNIX domain sockets to attach to another user's Xvnc session without providing authentication credentials, exploiting the missing authentication mechanism.
  5. View or control session: Once connected, the attacker can observe the victim's desktop, capture sensitive information, or inject keyboard/mouse input to control the session (GitHub Advisory).

Indicators of compromise

  • Process: Unexpected VNC client processes (e.g., vncviewer, xtightvncviewer) running under a user account other than the session owner; unusual connections to UNIX domain sockets belonging to other users.
  • Logs: xrdp session logs showing unexpected connection attempts or session attachments from users other than the session owner; audit logs (/var/log/audit/audit.log) recording unauthorized access to UNIX domain socket files.
  • File System: Unexpected access timestamps on UNIX domain socket files in /tmp/.X11-unix/ or similar directories by users who do not own those sessions.

Mitigation and workarounds

Upgrade xrdp to version 0.10.6.1, which contains the fix for this vulnerability. As a workaround, administrators can switch from the Xvnc backend over UNIX domain sockets to an unaffected backend such as xorgxrdp or configure Xvnc to use TCP sockets instead. Fedora users can apply the updated xrdp packages distributed via Fedora security updates (GitHub Advisory, Linux Security).

Community reactions

The vulnerability was disclosed by maintainer metalefty via the GitHub Security Advisory on July 1, 2026. Linux distribution security trackers and news outlets including LinuxSecurity.com and pro-linux.de covered the advisory shortly after publication, and Fedora issued updated packages. Tenable published Nessus detection plugins (325639 and 327222) to enable automated scanning for affected systems (Tenable Plugin, Linux Security, pro-linux.de).

Additional resources


SourceThis report was generated using AI

Related xrdp vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55626HIGH8
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-54538HIGH7.5
  • xrdp logoxrdp
  • cpe:2.3:a:neutrinolabs:xrdp
NoYesJul 20, 2026
CVE-2026-55645MEDIUM6.5
  • xrdp logoxrdp
  • xrdp-debugsource
NoYesJul 20, 2026
CVE-2026-55639MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026
CVE-2026-55238MEDIUM5.3
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management