CVE-2026-67295
Received Received - Intake

Path Traversal in FreeRDP Drive Redirection

Vulnerability report for CVE-2026-67295, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: VulnCheck

Description

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freerdp freerdp to 3.29.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FreeRDP before version 3.29.0 has a flaw where it does not properly validate server-supplied paths in drive redirection. This allows attackers controlling a malicious RDP server to access files outside the intended shared root directory by using non-rooted paths. This bypasses the boundary check meant to restrict access to only the shared folder.

Detection Guidance

Detecting this vulnerability requires monitoring for unauthorized file access or path traversal attempts in FreeRDP drive redirection. Check FreeRDP logs for suspicious path requests or failed validation events. Use network monitoring tools to inspect RDP traffic for non-rooted paths being sent by RDP servers.

Impact Analysis

If you connect to a malicious RDP server, an attacker could read, write, delete, or list files in directories adjacent to the shared folder on your system. This could lead to data theft, unauthorized modifications, or system compromise depending on the files accessed.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Organizations using vulnerable FreeRDP versions may face compliance violations, data breach notifications, and potential fines if exploited.

Mitigation Strategies

Immediately upgrade FreeRDP to version 3.29.0 or later to patch the vulnerability. Disable drive redirection in RDP clients if not required. Restrict RDP server access to trusted sources only. Monitor for unusual file access patterns in shared directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67295. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart