FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, the handshake dispatches inbound PDUs based solely on the attacker-supplied wire pduType without verifying that the received PDU is the one required at the current step. Because the rdpRdstls object is calloc-zeroed, its resultCode defaults to 0 (RDSTLS_RESULT_SUCCESS). An unauthenticated remote client can send a Capabilities PDU instead of the required Authentication Request PDU; rdstls_process_capabilities() returns success without ever setting resultCode, so the server responds with an AUTHRSP carrying resultCode SUCCESS and treats the session as authenticated without evaluating any password, redirection GUID, or auto-reconnect cookie. This affects the released FreeRDP 3.x series (e.g., 3.27.1) and master HEAD; at the time of the advisory no patched version was available.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-72746 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.
CVE-2026-72746
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.5
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- 0%
- EPSS %ILE
- 36%
- KEV
- Not listed
Published
August 11, 2026
Last Modified
August 11, 2026
Advisory Details (3)
Auto-updated Aug 11, 2026FreeRDP before 3.30.0 RDSTLS Server Authentication Bypass via PDU-type Confusion | Advisories | VulnCheck
https://www.vulncheck.com/advisories/freerdp-before-rdstls-server-authentication-bypass-via-pdu-type-confusioncommit b05a9510787c (FreeRDP/FreeRDP)
Fix landed in FreeRDP/FreeRDP commit b05a9510787c — awaiting tagged release
https://github.com/FreeRDP/FreeRDP/commit/b05a9510787c83c87ffc5fa8d7cc9f06ed971695RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`) · Advisory · FreeRDP/FreeRDP · GitHub
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6xVendor Advisories for CVE-2026-72746(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 3× in last 7d / 13× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-21 05:46 UTCGHSA enrichment
- 2026-08-18 09:54 UTCGHSA enrichment
- 2026-08-15 14:02 UTCGHSA enrichment
- 2026-08-12 18:10 UTCEG score recompute▼ 7.50
- 2026-08-12 18:10 UTCGHSA enrichment
- 2026-08-12 13:51 UTCEPSS rescore
- 2026-08-12 05:23 UTCGHSA enrichment
- 2026-08-11 16:36 UTCEG score recompute
- 2026-08-11 16:36 UTCGHSA enrichment
- 2026-08-11 15:22 UTCEG score recompute
- 2026-08-11 13:25 UTCEG score recompute
- 2026-08-11 12:22 UTCEG score recompute
- 2026-08-11 12:22 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Same CWE
10 shownCWE-287
Frequently asked(5)
What is CVE-2026-72746?
When was CVE-2026-72746 disclosed?
Is CVE-2026-72746 actively exploited?
What is the CVSS score of CVE-2026-72746?
How do I remediate CVE-2026-72746?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-72746
Is Your Infrastructure Affected by CVE-2026-72746?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.