Sceawere

Vulnerability Detail

CVE-2026-91949UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FreeRDP RDSTLS Protocol Negotiation Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
3h ago
Vendor
FreeRDP
Product
FreeRDP
Attack Type
Protection Mechanism Failure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-09-15T16:17:48.653Z",
  "pubdate": "2026-09-15T16:17:48.653Z",
  "executiveSummary": "A critical protocol negotiation vulnerability exists in FreeRDP server versions prior to 3.31.0, allowing unauthenticated attackers to bypass configured security policies regarding RDSTLS connections.\nThe vulnerability allows an attacker to force the establishment of an RDSTLS transport layer even when the server has explicitly disabled it via policy configuration.\nThis flaw effectively circumvents pre-authentication transport security restrictions, exposing the server to unauthorized connection attempts.\nThe impact is significant as it weakens the overall security posture by rendering transport-layer enforcement ineffective, potentially facilitating further exploitation of the Remote Desktop Protocol (RDP) stack.\nThe attacker requires network access to the target FreeRDP server but does not need prior authentication to trigger the flaw, making it a high-risk entry point for remote exploitation.",
  "technicalDetails": "The vulnerability resides in the protocol negotiation logic of the FreeRDP server component, which fails to correctly enforce transport security policies during the initial handshake phases.\nThe root cause involves improper state management during the protocol negotiation sequence. When an attacker sends a series of incompatible protocol requests, the server correctly identifies these as failures. However, the subsequent state transition logic does not adequately lock or terminate the negotiation context when these specific failures occur.\nAttack flow involves the following steps: first, the attacker initiates a connection and sends a deliberate sequence of incompatible protocol requests designed to trigger a negotiation failure within the FreeRDP server. Second, due to the flaw in the state machine, the server fails to properly invalidate the connection context or enforce the existing policy that disables RDSTLS. Third, the attacker proceeds to complete a standard TLS handshake. Because the internal state was not correctly reset or restricted by the previous failure, the server erroneously permits the connection to transition into the RDSTLS transport mode.\nBy bypassing the pre-authentication transport restrictions, the attacker forces the server to accept an RDSTLS connection that should have been rejected or downgraded to a compliant transport method. This provides the attacker with a functional communication channel that violates the server's security configuration.\nThis vulnerability is present in all FreeRDP server versions before 3.31.0. It is a remote, unauthenticated vulnerability requiring only network connectivity to the target port. No specific administrative or user privileges are required for the initial exploitation, as the flaw exists at the protocol negotiation layer, which precedes the authentication phase of the RDP connection process.\nThe post-exploitation impact primarily involves the ability to force the server into a non-compliant state, enabling the use of prohibited transport methods that may facilitate secondary RDP-based attacks or reconnaissance against the host."
}
CVE-2026-91949: FreeRDP RDSTLS Protocol Negotiation Bypass (CRITICAL Severity, CVSS: 9.3) | Sceawere