Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-91949: FreeRDP before 3.31 allows unauthorized remote desktop connections
CVE-2026-91949 · published 25 days ago
Summary
Versions of FreeRDP released before 3.31 let an attacker who is not logged in trick the server into opening a secure remote desktop session, even when the server is set to block that type of connection. This means a malicious user could bypass the server's transport restrictions and gain remote access. Update FreeRDP to version 3.31 or later, or apply any available patches, to close the bypass.
What to do
- Update debian freerdp3 to version 3.31.0+dfsg-1.
- Update canonical freerdp3 to version 3.31.0+dfsg-0ubuntu0.24.04.1.
- Update canonical freerdp3 to version 3.31.0+dfsg-0ubuntu0.26.04.1.
- Update freerdp freerdp to version 3.31.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | freerdp | freerdp |
< 3.31.0 >= 3.0.0, < 3.31.0 |
| Debian:13 | debian | freerdp3 | All versions |
| Debian:14 | debian | freerdp3 |
< 3.31.0+dfsg-1 Fix: upgrade to 3.31.0+dfsg-1
|
| Ubuntu:16.04:LTS | canonical | freerdp | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | freerdp2 | All versions |
| Ubuntu:24.04:LTS | canonical | freerdp3 |
< 3.31.0+dfsg-0ubuntu0.24.04.1 Fix: upgrade to 3.31.0+dfsg-0ubuntu0.24.04.1
|
| Ubuntu:26.04:LTS | canonical | freerdp3 |
< 3.31.0+dfsg-0ubuntu0.26.04.1 Fix: upgrade to 3.31.0+dfsg-0ubuntu0.26.04.1
|
Original advisory text
FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
References
- https://security-tracker.debian.org/tracker/CVE-2026-91949 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-91949 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-91949 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-91949 Vendor Advisory
- https://www.openwall.com/lists/oss-security/2026/09/01/2 Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6 Exploit Mitigation Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91949... Vendor Advisory
- https://www.vulncheck.com/advisories/freerdp-3.0.0-through-3.30.0-protocol-negot... Third Party Advisory
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
9.2
Critical
Type
CWE-693Protection Mechanism Failure
Timeline
Published15 Sep 2026
Updated9 Oct 2026
First seen15 Sep 2026
Sources
CVE-2026-91949 · NVD
CVE-2026-91949 · MITRE
DEBIAN-CVE-2026-91949 · OSV
CVE-2026-91949 · OSV
GHSA-x7v6-xfx3-52j6 · GHSA
UBUNTU-CVE-2026-91949 · OSV
Track software like this
Free during beta