Description
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
Published: 2026-09-15
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass that allows unauthenticated attackers to send incompatible protocol requests, trigger negotiation failures, then complete a TLS handshake and enter RDSTLS mode. This bypasses any server policy that restricts RDSTLS before authentication, effectively granting an attacker the ability to establish an encrypted RDP session without proper authentication. The flaw is classified as CWE-358 and CWE-693.

Affected Systems

Affected vendors include FreeRDP. The product FreeRDP, versions from 3.0.0 up to and including 3.30.0, are vulnerable.

Risk and Exploitability

Based on the description, it is inferred that attackers can exploit this vulnerability remotely over the network by sending specially crafted protocol requests to a vulnerable FreeRDP server. The flaw enables an unauthenticated attacker to complete a TLS handshake and enter RDSTLS mode even when the server policy disables RDSTLS before authentication. The EPSS score indicates a very low but non-zero probability of exploitation, while the CVSS score of 9.2 reflects critical severity. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 21, 2026 at 14:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.31.0 or later.
  • Block inbound RDP traffic or deny RDSTLS connections at the network perimeter.
  • Restrict inbound RDP traffic to known IP addresses using firewall rules.

Generated by OpenCVE AI on September 21, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-358
References
Metrics threat_severity

None

threat_severity

Critical


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
Title FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-693
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:28:33.068Z

Reserved: 2026-09-15T11:07:34.398Z

Link: CVE-2026-91949

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:28.847Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:48.653

Modified: 2026-09-24T12:14:46.820

Link: CVE-2026-91949

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-15T15:18:07Z

Links: CVE-2026-91949 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T15:00:18Z

Weaknesses
  • CWE-358

    Improperly Implemented Security Check for Standard

  • CWE-693

    Protection Mechanism Failure