CVE-2026-91949
Publication date 15 September 2026
Last updated 24 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| freerdp | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| freerdp2 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| freerdp3 | 26.04 LTS resolute |
Fixed 3.31.0+dfsg-0ubuntu0.26.04.1
|
| 24.04 LTS noble |
Fixed 3.31.0+dfsg-0ubuntu0.24.04.1
|
|
| 22.04 LTS jammy | Not in release |
Severity score breakdown
CVSS version:
Base score
9.2 · Critical
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
Base score
9.3 · Critical
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N