CVE-2026-55639
xrdp vulnerability analysis and mitigation

Overview

CVE-2026-55639 is an improper input validation vulnerability in xrdp's MCS data processing that can lead to a potential information leak. It affects xrdp versions through 0.10.6, with the patched version being 0.10.6.1. The flaw was discovered by researcher TristanInSec and published on July 2, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 5.3 (Moderate) (GitHub Advisory).

Technical details

The root cause is an out-of-bounds read (CWE-125) in xrdp's parser for Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request, processed during the RDP connection sequence. The parser fails to perform sufficient length validation on the incoming data block, allowing a remote, unauthenticated attacker to send a specially crafted RDP packet with malformed data. Due to missing bounds checks, the xrdp process may read a small number of bytes beyond the declared data block boundary, potentially exposing process memory contents (GitHub Advisory).

Impact

Successful exploitation results in a low-severity confidentiality impact — specifically, a small number of bytes of xrdp process memory may be disclosed to an unauthenticated remote attacker. There is no impact to integrity or availability. While the leaked memory content alone may be limited, it could potentially be chained with other vulnerabilities to facilitate further attacks (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible hosts running xrdp version 0.10.6 or earlier using network scanners (e.g., Shodan, Nmap with RDP service detection on TCP port 3389).
  2. Craft malicious RDP packet: Construct a Client MCS Connect Initial PDU with GCC Conference Create Request containing a malformed Client Security Data block where the declared length does not match the actual data size.
  3. Send crafted packet: Transmit the specially crafted RDP packet to the target xrdp server without any authentication credentials.
  4. Trigger out-of-bounds read: The xrdp parser, lacking sufficient bounds checks, reads beyond the declared data block boundary, potentially returning a small number of bytes of process memory in its response.
  5. Collect leaked memory: Capture and analyze the server's response for any leaked memory bytes, which could be used to inform further exploitation attempts (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or malformed RDP connection attempts (TCP port 3389) that do not complete a full handshake; repeated connection attempts from a single source IP sending non-standard Client MCS Connect Initial PDUs.
  • Logs: xrdp session logs showing connection attempts that terminate abnormally during the capability/security negotiation phase; error messages related to MCS or GCC data parsing.
  • Process: Unexpected xrdp process crashes or restarts that may indicate repeated exploitation attempts triggering memory access errors.

Mitigation and workarounds

The xrdp project has released version 0.10.6.1 as the patched release addressing this vulnerability. Administrators should upgrade to xrdp 0.10.6.1 or later as the primary remediation. As a temporary workaround where upgrading is not immediately possible, restricting network access to the xrdp service (TCP port 3389) via firewall rules to trusted IP ranges can reduce exposure (GitHub Advisory, Linux Security).

Community reactions

The vulnerability was reported by researcher TristanInSec and disclosed by xrdp maintainer metalefty via a GitHub Security Advisory on July 2, 2026. Fedora has issued security updates for xrdp addressing this issue, and coverage has appeared on Linux security news aggregators including LinuxSecurity.com and pro-linux.de (Linux Security, pro-linux.de).

Additional resources


SourceThis report was generated using AI

Related xrdp vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55626HIGH8
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-54538HIGH7.5
  • xrdp logoxrdp
  • cpe:2.3:a:neutrinolabs:xrdp
NoYesJul 20, 2026
CVE-2026-55645MEDIUM6.5
  • xrdp logoxrdp
  • xrdp-debugsource
NoYesJul 20, 2026
CVE-2026-55639MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026
CVE-2026-55238MEDIUM5.3
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management