Description

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.

INFO

Published Date :

2026-04-17T19:25:20.274Z

Last Modified :

2026-04-17T19:25:20.274Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-32107 vulnerability.

Vendors Products
Neutrinolabs
  • Xrdp

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact