CVE-2026-55626
描述
xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them to unauthorizedly view or control the active desktop sessions of other users on the same system. Users using other backends, such as xorgxrdp or Xvnc over TCP sockets, are not affected. This issue has been fixed in version 0.10.6.1.
如何修補 CVE-2026-55626
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
- Debian/xrdp—未列出修補版本
CVE-2026-55626 正在被利用嗎?
目前沒有被利用訊號。CVE-2026-55626 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(1)
- from 0