CVE-2026-73241Disclosure(freerdp / freerdp)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch freerdp freerdp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCode at RDSTLS_RESULT_SUCCESS and allowing a remote unauthenticated client to bypass the RedirectionGuid, username, domain, or password checks. This issue is fixed in version 3.30.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freerdp

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
freerdp

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-13: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 108-13
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • PatchHawk@patchhawk_
    Disclosure

    Same release, server side: an RDSTLS auth bypass (CVE-2026-73241, 8.3). RDSTLS_RESULT_SUCCESS is 0x00000000. The context comes from calloc. Reach the verdict without ever sending credentials and resultCode is still 0 — already "success." 3.30.0 defaults it to ACCESS_DENIED. https://t.co/KwYHOZLrPd

    Post summary

    The post describes an RDSTLS authentication bypass in a server release, detailing how a success code can be achieved without credentials, and notes the 3.30.0 default to ACCESS_DENIED as a mitigation, but provides no exploit code or evidence of active attacks.

    11010121
    56 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreerdpfreerdp---

Explore more