
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55626 is a missing authentication vulnerability in xrdp that allows local authenticated attackers to bypass session isolation and access or control other users' active desktop sessions. It affects xrdp versions 0.10.3 through 0.10.6 when using the Xvnc backend over UNIX domain sockets. The vulnerability was published on July 1, 2026, and a patched version (0.10.6.1) has been released. It carries a CVSS v3.1 base score of 8.0 (High) (GitHub Advisory).
The root cause is insufficient authentication when xrdp launches the Xvnc process in UNIX domain socket mode during session initialization. When an authenticated user session is set up via the Xvnc backend over UNIX domain sockets, the spawned Xvnc process lacks adequate authentication controls, enabling a local attacker to connect to another user's Xvnc session without authorization. This is classified as a missing authentication for critical function issue. Notably, deployments using other backends — such as xorgxrdp or Xvnc over TCP sockets — are not affected by this vulnerability (GitHub Advisory).
A local authenticated attacker who successfully exploits this vulnerability can view or control the active desktop sessions of other users on the same system, resulting in high confidentiality and integrity impact and low availability impact. This could expose sensitive data visible on other users' desktops, allow unauthorized input injection into their sessions, and facilitate privilege escalation or lateral movement within a multi-user environment (GitHub Advisory).
ss -x or inspecting /tmp/.X11-unix/) to locate Xvnc sockets associated with other users' xrdp sessions.vncviewer, xtightvncviewer) running under a user account other than the session owner; unusual connections to UNIX domain sockets belonging to other users./var/log/audit/audit.log) recording unauthorized access to UNIX domain socket files./tmp/.X11-unix/ or similar directories by users who do not own those sessions.Upgrade xrdp to version 0.10.6.1, which contains the fix for this vulnerability. As a workaround, administrators can switch from the Xvnc backend over UNIX domain sockets to an unaffected backend such as xorgxrdp or configure Xvnc to use TCP sockets instead. Fedora users can apply the updated xrdp packages distributed via Fedora security updates (GitHub Advisory, Linux Security).
The vulnerability was disclosed by maintainer metalefty via the GitHub Security Advisory on July 1, 2026. Linux distribution security trackers and news outlets including LinuxSecurity.com and pro-linux.de covered the advisory shortly after publication, and Fedora issued updated packages. Tenable published Nessus detection plugins (325639 and 327222) to enable automated scanning for affected systems (Tenable Plugin, Linux Security, pro-linux.de).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."