Skip to content
Verified reproduction

CVE-2026-55626: xrdp Xvnc backend authentication issue on RHEL 9

CVE-2026-55626 is verified against neutrinolabs/xrdp · github affected versions: GitHub advisory range is xrdp 0.10.3 through 0.10.6 inclusive. The RHEL 9 report reproduced on xrdp-0.10.6-1.el9.x86_64. This high reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00311.

REPRO-2026-00311 neutrinolabs/xrdp · github Jul 29, 2026 CVE entry .txt
Severity HIGH
Confidence HIGH
Reproduced in 64m 30s
Tool calls 432
Spend $45.26
Affected GitHub advisory range is xrdp 0.10.3 through 0.10.6 inclusive. The RHEL 9 report reproduced on xrdp-0.10.6-1.el9.x86_64.
$ pruva-verify REPRO-2026-00311
or curl -O https://pruva.dev/api/v1/reproductions/REPRO-2026-00311/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh
Run in a VM or disposable container. This exploits a real vulnerability.
02 · The vulnerability

xrdp is affected by an authentication issue in the Xvnc backend on RHEL 9 deployments. The issue can weaken or bypass expected authentication controls in the backend path used to start remote desktop sessions. The affected deployment is the Xvnc backend on RHEL 9.

03 · Root cause
04 · Reproduction transcript

The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.

Loading session...

05 · Artifacts

Scripts, logs, diffs, and output captured during the reproduction.