Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-55626

2 месяца назад

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them to unauthorizedly view or control the active desktop sessions of other users on the same system. Users using other backends, such as xorgxrdp or Xvnc over TCP sockets, are not affected. This issue has been fixed in version 0.10.6.1.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2026-55626

2 месяца назад

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them to unauthorizedly view or control the active desktop sessions of other users on the same system. Users using other backends, such as xorgxrdp or Xvnc over TCP sockets, are not affected. This issue has been fixed in version 0.10.6.1.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2026-55626

2 месяца назад

xrdp is an open source RDP server. In versions 0.10.6 and prior, when ...

CVSS3: 8
EPSS: Низкий
redos логотип

ROS-20260818-80-0040

около 1 месяца назад

Уязвимость xrdp

CVSS3: 7.3
EPSS: Низкий
redos логотип

ROS-20260818-73-0044

около 1 месяца назад

Уязвимость xrdp

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them to unauthorizedly view or control the active desktop sessions of other users on the same system. Users using other backends, such as xorgxrdp or Xvnc over TCP sockets, are not affected. This issue has been fixed in version 0.10.6.1.

CVSS3: 8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them to unauthorizedly view or control the active desktop sessions of other users on the same system. Users using other backends, such as xorgxrdp or Xvnc over TCP sockets, are not affected. This issue has been fixed in version 0.10.6.1.

CVSS3: 8
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when ...

CVSS3: 8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260818-80-0040

Уязвимость xrdp

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260818-73-0044

Уязвимость xrdp

CVSS3: 7.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу