High severity7.5NVD Advisory· Published Aug 11, 2026· Updated Sep 25, 2026
CVE-2026-73241
CVE-2026-73241
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCode at RDSTLS_RESULT_SUCCESS and allowing a remote unauthenticated client to bypass the RedirectionGuid, username, domain, or password checks. This issue is fixed in version 3.30.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords6 versionspkg:rpm/almalinux/freerdp-libspkg:rpm/almalinux/freerdp-develpkg:rpm/almalinux/freerdppkg:rpm/almalinux/freerdp-serverpkg:rpm/almalinux/libwinprpkg:rpm/almalinux/libwinpr-devel
< 2:3.10.3-12.el10_2.10+ 5 more
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
Patches
Vulnerability mechanics
References
4- github.com/FreeRDP/FreeRDP/commit/b05a9510787c83c87ffc5fa8d7cc9f06ed971695nvdPatch
- github.com/FreeRDP/FreeRDP/pull/13065nvdIssue TrackingPatch
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6xnvdExploitMitigationVendor Advisory
- github.com/FreeRDP/FreeRDP/releases/tag/3.30.0nvdRelease Notes
News mentions
1- FreeRDP: Four High Severity Flaws in RDSTLS and Kerberos Patched TogetherVypr Intelligence · Aug 11, 2026