CVE-2026-91949 PUBLISHED

FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass

Assigner: VulnCheck
Reserved: 15.09.2026 Published: 15.09.2026 Updated: 15.09.2026

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
CVSS Score: 9.2

Product Status

Vendor FreeRDP
Product FreeRDP
Versions Default: unaffected
  • affected from 3.0.0 to 3.31.0 (excl.)
  • Version 3.31.0 is unaffected

Credits

  • sam4k reporter

References

Problem Types

  • Protection Mechanism Failure CWE