PT-2026-70897 · Freerdp · Freerdp

CVE-2026-73241

·

Published

2026-08-11

·

Updated

2026-08-31

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.30.0
Description Server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS TYPE CAPABILITIES PDU while the rdstls server authenticate() function is waiting for RDSTLS TYPE AUTHREQ. This leaves the resultCode variable at RDSTLS RESULT SUCCESS, which allows a remote unauthenticated client to bypass checks for the RedirectionGuid, username, domain, or password.
Recommendations Update to version 3.30.0.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61378
CVE-2026-73241
GHSA-RQGV-GRX4-XM6X

Affected Products

Freerdp