---
id: CVE-2026-91949
title: >-
  FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass
  vulnerability that allows unauthenticated attackers to establish RDSTLS
  connections despite server policy disabling them
summary: >-
  FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass
  vulnerability that allows unauthenticated attackers to establish RDSTLS
  connections despite server policy disabling them. Attackers can send
  incompatible protoco…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-693
  - CWE-358
vendor: freerdp
product: freerdp
affected:
  - 'freerdp >= 3.0.0, < 3.31.0'
patched:
  - freerdp 3.31.0
published: '2026-09-15'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T12:14:46.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91949'
references:
  - url: 'https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/freerdp-3.0.0-through-3.30.0-protocol-negotiation-bypass
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91949.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-91949'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2533925'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-91949'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91949'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00466
epssPercentile: 0.37581
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T19:15:27.791401Z'
ingestedAt: '2026-09-15T15:39:12.919Z'
---

## Overview

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.

## Affected

- `freerdp >= 3.0.0, < 3.31.0`

## Remediation

Upgrade past the affected range:

- `freerdp 3.31.0`

## Vendor advisories

- **Red Hat VEX** · Critical · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91949.json)
