Improper Check for Dropped Privileges Affecting xrdp package, versions <0.10.6-r0


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALPINE323-XRDP-16159854
  • published23 Apr 2026
  • disclosed17 Apr 2026

Introduced: 17 Apr 2026

CVE-2026-32107  (opens in a new tab)
CWE-273  (opens in a new tab)

How to fix?

Upgrade Alpine:3.23 xrdp to version 0.10.6-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream xrdp package and not the xrdp package as distributed by Alpine. See How to fix? for Alpine:3.23 relevant fixed versions and status.

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.