CVE-2026-35512
Severity CVSS v4.0:
HIGH
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
17/04/2026
Last modified:
27/04/2026
Description
xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:* | 0.10.6 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



