CVE-2026-72746

EUVD-2026-56136
FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, the handshake dispatches inbound PDUs based solely on the attacker-supplied wire pduType without verifying that the received PDU is the one required at the current step. Because the rdpRdstls object is calloc-zeroed, its resultCode defaults to 0 (RDSTLS_RESULT_SUCCESS). An unauthenticated remote client can send a Capabilities PDU instead of the required Authentication Request PDU; rdstls_process_capabilities() returns success without ever setting resultCode, so the server responds with an AUTHRSP carrying resultCode SUCCESS and treats the session as authenticated without evaluating any password, redirection GUID, or auto-reconnect cookie. This affects the released FreeRDP 3.x series (e.g., 3.27.1) and master HEAD; at the time of the advisory no patched version was available.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulnCheckCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
freerdpfreerdp
3.0.0 ≤
𝑥
< 3.30.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
freerdp2
bookworm
2.11.7+dfsg1-6~deb12u1
fixed
bullseye
2.3.0+dfsg1-2+deb11u1
fixed
bullseye (security)
2.3.0+dfsg1-2+deb11u3
fixed
freerdp3
forky
3.30.0+dfsg-1
fixed
sid
3.30.0+dfsg-1
fixed
trixie
vulnerable