CVE-2026-42218
Description
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on the system, leading to unauthorized information disclosure via username enumeration. This issue has been fixed in version 0.10.6.1.
How to fix CVE-2026-42218
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/xrdp—no fix listed
Is CVE-2026-42218 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-42218.
Affected packages (1)
- from 0