What is CVE-2026-67294?
In FreeRDP versions before 3.29.0, client-side server TLS authentication improperly validates the Extended Key Usage (EKU) purpose of the peer certificate. When server-purpose (X509_PURPOSE_SSL_SERVER) verification fails in x509_utils_verify(), the code falls back to client-purpose, potentially leading to weak authentication. Affected users should immediately update FreeRDP to at least version 3.29.0.
Azərbaycanca: FreeRDP-nin 3.29.0-dan əvvəlki versiyalarında müştəri tərəfində server TLS autentifikasiyası zamanı peer sertifikatının Extended Key Usage (EKU) məqsədi düzgün yoxlanılmır. X509_utils_verify() funksiyasında server məqsədi (X509_PURPOSE_SSL_SERVER) uğursuz olduqda, kod səhvən müştəri məqsədinə keçid edir ki, bu da zəif autentifikasiyaya səbəb ola bilər. Təsirə məruz qalan istifadəçilər dərhal FreeRDP-ni ən azı 3.29.0 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: FreeRDP
FAQ2
Which versions of FreeRDP are affected by CVE-2026-67294?
FreeRDP versions before 3.29.0 are affected.
What should users do to address the CVE-2026-67294 vulnerability?
Users should immediately update FreeRDP to at least version 3.29.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.