Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-55626
xrdp vulnerability analysis and mitigation

Overview

CVE-2026-55626 is a missing authentication vulnerability in xrdp, an open-source RDP server, that allows a local authenticated attacker to bypass session isolation and view or control the active desktop sessions of other users on the same system. It affects xrdp versions 0.10.3 through 0.10.6 when using the Xvnc backend over UNIX domain sockets; users of xorgxrdp or Xvnc over TCP sockets are not affected. The vulnerability was published on July 20, 2026, and patched in version 0.10.6.1 released July 6, 2026. It carries a CVSS v3.1 base score of 7.3 (High) per NVD, and 8.0 (High) per the GitHub Security Advisory (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function). When xrdp initializes an authenticated user session using the Xvnc backend over UNIX domain sockets, it launches the Xvnc process without enforcing adequate authentication controls, failing to properly isolate the session from other users' active desktop sessions. A local attacker who already has a valid account on the system can exploit this weakness to connect to or interact with another user's Xvnc session running over the UNIX domain socket, effectively hijacking or spying on that session. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows a local authenticated attacker to bypass intended session isolation, enabling unauthorized viewing or control of other users' active desktop sessions on the same system. This results in high confidentiality and integrity impact — an attacker could observe sensitive on-screen data, capture credentials, or manipulate applications running in another user's session. Availability impact is rated low. The vulnerability is scoped to multi-user systems running xrdp with the Xvnc-over-UNIX-domain-socket configuration, and does not enable remote exploitation or direct privilege escalation to root, but could facilitate lateral movement within a shared host environment (GitHub Advisory, Red Hat).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.205%, indicating a low probability of exploitation in the near term. Exploitation requires local authenticated access to the target system, limiting the attacker pool to users with existing accounts (GitHub Advisory, Red Hat).

Exploitation steps

  1. Gain local access: Obtain a valid local user account on a multi-user Linux system running xrdp with the Xvnc backend configured over UNIX domain sockets (versions 0.10.3–0.10.6).
  2. Identify active sessions: Enumerate active xrdp/Xvnc sessions on the system, for example by listing UNIX domain socket files in /tmp or /var/run associated with Xvnc processes (e.g., using ls /tmp/.X*-lock or ps aux | grep Xvnc).
  3. Connect to target socket: Use a VNC client or tool capable of connecting over UNIX domain sockets to attach to another user's Xvnc session socket, bypassing the missing authentication check.
  4. View or control session: Once connected, the attacker can observe the victim's active desktop, capture on-screen credentials or sensitive data, or interact with applications running in the victim's session (GitHub Advisory).

Indicators of compromise

  • Process: Unexpected VNC client processes (e.g., vncviewer, xtightvncviewer) running under a user account other than the session owner; processes connecting to UNIX domain sockets belonging to other users' Xvnc sessions.
  • File System: Unusual access timestamps on UNIX domain socket files in /tmp (e.g., .X<display>-unix) by users other than the session owner; unexpected .Xauthority file access patterns.
  • Logs: xrdp session logs (/var/log/xrdp.log, /var/log/xrdp-sesman.log) showing session connection events from unexpected user accounts; system audit logs (/var/log/audit/audit.log) recording cross-user socket access events.
  • Network: No network-based IOCs apply, as exploitation occurs entirely over local UNIX domain sockets.

Mitigation and workarounds

The primary remediation is to upgrade xrdp to version 0.10.6.1 or later, which was released on July 6, 2026, and addresses this vulnerability along with nine others (xrdp Release). If an immediate upgrade is not possible, administrators should switch to an unaffected backend such as xorgxrdp or configure Xvnc to use TCP sockets instead of UNIX domain sockets. Additionally, restricting local user access to the system and applying the principle of least privilege can reduce the risk of exploitation (GitHub Advisory, Red Hat).

Community reactions

The vulnerability was disclosed via a GitHub Security Advisory by xrdp maintainer metalefty on July 1, 2026, and was part of a batch fix addressing 10 vulnerabilities in the v0.10.6.1 release. Red Hat tracked the issue via Bugzilla and assigned it a high severity rating. Fedora issued updated packages, and the issue received coverage in Linux security news outlets including linuxsecurity.com and pro-linux.de (GitHub Advisory, xrdp Release, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

xrdp

Fixed

sid

xrdp: 0.10.6.1-2

Fixed

trixie

xrdp

Fixed

Ubuntu

Unknown

bionic (esm-apps)

xrdp

Unknown

devel

xrdp

Unknown

focal (esm-apps)

xrdp

Unknown

jammy

xrdp

Unknown

jammy (esm-apps)

xrdp

Unknown

noble

xrdp

Unknown

noble (esm-apps)

xrdp

Unknown

resolute

xrdp

Unknown

SourceThis report was generated using AI

Related xrdp vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54538HIGH7.5
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-55626HIGH7.3
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-55645MEDIUM6.5
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026
CVE-2026-55639MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-devel
NoYesJul 20, 2026
CVE-2026-55238MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management