Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | FreeRDP before 3.30.0 RDSTLS Server Authentication Bypass via PDU-type Confusion | FreeRDP: FreeRDP: Authentication bypass in RDSTLS handshake via PDU-type confusion |
| Metrics |
ssvc
|
Wed, 12 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV4_0
|
Wed, 12 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, the handshake dispatches inbound PDUs based solely on the attacker-supplied wire pduType without verifying that the received PDU is the one required at the current step. Because the rdpRdstls object is calloc-zeroed, its resultCode defaults to 0 (RDSTLS_RESULT_SUCCESS). An unauthenticated remote client can send a Capabilities PDU instead of the required Authentication Request PDU; rdstls_process_capabilities() returns success without ever setting resultCode, so the server responds with an AUTHRSP carrying resultCode SUCCESS and treats the session as authenticated without evaluating any password, redirection GUID, or auto-reconnect cookie. This affects the released FreeRDP 3.x series (e.g., 3.27.1) and master HEAD; at the time of the advisory no patched version was available. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241. |
| CPEs | cpe:2.3:a:freerdp:freerdp:3.23.0:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.24.0:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.24.1:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.24.2:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.25.0:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.26.0:*:*:*:*:*:*:* |
|
| Metrics |
cvssV4_0
|
cvssV4_0
|
Wed, 12 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1287 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, the handshake dispatches inbound PDUs based solely on the attacker-supplied wire pduType without verifying that the received PDU is the one required at the current step. Because the rdpRdstls object is calloc-zeroed, its resultCode defaults to 0 (RDSTLS_RESULT_SUCCESS). An unauthenticated remote client can send a Capabilities PDU instead of the required Authentication Request PDU; rdstls_process_capabilities() returns success without ever setting resultCode, so the server responds with an AUTHRSP carrying resultCode SUCCESS and treats the session as authenticated without evaluating any password, redirection GUID, or auto-reconnect cookie. This affects the released FreeRDP 3.x series (e.g., 3.27.1) and master HEAD; at the time of the advisory no patched version was available. | |
| Title | FreeRDP before 3.30.0 RDSTLS Server Authentication Bypass via PDU-type Confusion | |
| First Time appeared |
Freerdp
Freerdp freerdp |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:freerdp:freerdp:2.11.8:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.23.0:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.24.0:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.24.1:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.24.2:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.25.0:*:*:*:*:*:*:* cpe:2.3:a:freerdp:freerdp:3.26.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Freerdp
Freerdp freerdp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-08-12T16:58:13.054Z
Reserved: 2026-08-10T13:53:42.482Z
Link: CVE-2026-72746
Updated:
Status : Rejected
Published: 2026-08-11T13:19:05.520
Modified: 2026-08-12T17:17:31.793
Link: CVE-2026-72746
OpenCVE Enrichment
Updated: 2026-08-12T00:00:03Z