CVE-2026-42218
EUVD-2026-4602420.07.2026, 17:17
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on the system, leading to unauthorized information disclosure via username enumeration. This issue has been fixed in version 0.10.6.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| neutrinolabs | xrdp | 𝑥 < 0.10.6.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration