A vulnerability was found in neutrinolabs xrdp up to 0.10.5. It has been declared as critical. This vulnerability affects unknown code of the file xrdp.ini of the component FIPS-specific receive paths. Executing a manipulation can lead to improper input validation.

This vulnerability is registered as CVE-2026-44978. It is possible to launch the attack remotely. No exploit is available.