Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-91949: FreeRDP before 3.31 allows unauthorized remote desktop connections

CVE-2026-91949 · published 25 days ago
Summary

Versions of FreeRDP released before 3.31 let an attacker who is not logged in trick the server into opening a secure remote desktop session, even when the server is set to block that type of connection. This means a malicious user could bypass the server's transport restrictions and gain remote access. Update FreeRDP to version 3.31 or later, or apply any available patches, to close the bypass.

What to do
  • Update debian freerdp3 to version 3.31.0+dfsg-1.
  • Update canonical freerdp3 to version 3.31.0+dfsg-0ubuntu0.24.04.1.
  • Update canonical freerdp3 to version 3.31.0+dfsg-0ubuntu0.26.04.1.
  • Update freerdp freerdp to version 3.31.0 or later.
Affected software
Ecosystem VendorProductAffected versions
– freerdp freerdp < 3.31.0
>= 3.0.0, < 3.31.0
Debian:13 debian freerdp3 All versions
Debian:14 debian freerdp3 < 3.31.0+dfsg-1
Fix: upgrade to 3.31.0+dfsg-1
Ubuntu:16.04:LTS canonical freerdp All versions
Ubuntu:Pro:18.04:LTS canonical freerdp2 All versions
Ubuntu:24.04:LTS canonical freerdp3 < 3.31.0+dfsg-0ubuntu0.24.04.1
Fix: upgrade to 3.31.0+dfsg-0ubuntu0.24.04.1
Ubuntu:26.04:LTS canonical freerdp3 < 3.31.0+dfsg-0ubuntu0.26.04.1
Fix: upgrade to 3.31.0+dfsg-0ubuntu0.26.04.1
Original advisory text
FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-693Protection Mechanism Failure
Timeline
Published15 Sep 2026
Updated9 Oct 2026
First seen15 Sep 2026
Track software like this
Free during beta