Description
xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.
INFO
Published Date :
2026-04-17T19:25:20.274Z
Last Modified :
2026-04-17T19:25:20.274Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-32107 vulnerability.
| Vendors | Products |
|---|---|
| Neutrinolabs |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-32107.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact