CVE-2026-55639: xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)

Published Jul 20, 2026
·
Updated

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. During the initial capability and security negotiation phase, the parser fails to perform sufficient length validation for the incoming data block. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed data. Due to missing bounds checks, the xrdp process may read a small number of bytes beyond the declared data block boundary, potentially disclosing process memory contents that could be combined with other vulnerabilities. This issue has been fixed in version 0.10.6.1.

Affected Software

2 affected components
xrdp<0.10.6.1
Neutrinolabs Xrdp<0.10.6.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade xrdp to a version that resolves this vulnerability.

    Fixed in 0.10.6.1
  2. Operational

    Update xrdp from versions 0.10.6 and prior to 0.10.6.1 to remediate the out-of-bounds read in xrdp_sec_process_mcs_data_CS_SECURITY (GCC Conference Create Request CS_SECURITY processing).

Event History

Jul 20, 2026
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-55639?

CVE-2026-55639 has a medium severity score of 5.3.

2

What software is affected by CVE-2026-55639?

The vulnerability affects xrdp versions 0.10.6 and prior.

3

How do I fix CVE-2026-55639?

To fix CVE-2026-55639, upgrade xrdp to version 0.10.6.1 or later.

4

What type of vulnerability is CVE-2026-55639?

CVE-2026-55639 is classified as an out-of-bounds read vulnerability.

5

What issues can CVE-2026-55639 cause?

CVE-2026-55639 can potentially allow for unintended access to memory during the security negotiation phase.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203