CVE-2026-42218: XRDP is vulnerable to a server timing attack, leading to user enumeration
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on the system, leading to unauthorized information disclosure via username enumeration. This issue has been fixed in version 0.10.6.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
xrdpto a version that resolves this vulnerability.Fixed in 0.10.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42218?
CVE-2026-42218 has a medium severity score of 5.3.
How do I fix CVE-2026-42218?
To fix CVE-2026-42218, upgrade to xrdp version 0.10.6.1 or later.
What type of attack does CVE-2026-42218 expose users to?
CVE-2026-42218 exposes users to a server timing attack that can lead to user enumeration.
Which software is affected by CVE-2026-42218?
CVE-2026-42218 affects xrdp versions 0.10.6 and prior.
What information can an attacker gain from CVE-2026-42218?
An attacker can infer the existence of usernames on the system due to timing discrepancies in response processing.