CVE-2026-91949
largeUnauthenticated RDSTLS Negotiation Bypass in FreeRDP Server before 3.31.0
FreeRDP servers before version 3.31.0 contain a protocol negotiation bypass (CWE-693, protection mechanism failure) in which the server fails to enforce its own configured transport restrictions during RDP protocol selection. An unauthenticated remote attacker sends deliberately incompatible protocol negotiation requests, receives the expected negotiation failure response, but is still allowed to complete the TLS handshake and enter an RDSTLS session even when the server's policy explicitly disables RDSTLS. This effectively bypasses pre-authentication transport restrictions, giving the attacker an authenticated-looking channel into the RDP server without valid credentials, with the CVSS 4.0 vector indicating high confidentiality impact on the vulnerable and subsequent systems. Any deployment exposing a FreeRDP-based server (including products embedding FreeRDP) on an older version is affected, with the greatest risk to internet-exposed RDP endpoints. No public proof of concept is known and there is no evidence of in-the-wild exploitation at this time.
What to do: Upgrade FreeRDP server to version 3.31.0 or later immediately; if you run a vendor product that embeds FreeRDP (thin clients, remote access gateways, Linux terminal servers), check with the vendor for a patched build and update promptly. Until patched, remove RDP endpoints from direct internet exposure (restrict to VPN or allowlisted gateways) and audit logs for the attack signature: protocol negotiation failure responses followed by completed TLS handshakes and RDSTLS sessions.
| FreeRDP (server component, including freerdp-shadow-server and third-party products embedding FreeRDP) | before 3.31.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
- Weakness
- CWE-693
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.