CVE-2026-91949: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Fixed in 3.31.0 - Compensating control
Until upgraded, restrict network access to the FreeRDP server (RDSTLS/RDP services) so unauthenticated attackers cannot reach it.
Event History
Frequently Asked Questions
Which deployments are affected?
FreeRDP Server versions 3.0.0 through 3.30.0 are affected. The issue is relevant where the server policy is intended to disable RDSTLS connections as a pre-authentication transport restriction.
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction. They can send incompatible protocol requests, receive negotiation failures, and then complete a TLS handshake to enter RDSTLS.
What is the remediation?
Upgrade FreeRDP Server to version 3.31.0 or later. Versions before 3.31.0 contain the protocol negotiation bypass.