A vulnerability, which was classified as critical, was found in FreeRDP up to 3.28.0. Affected by this issue is the function rail_server_handle_messages of the file channels/rail/server/rail_main.c of the component RAIL Channel Handler. The manipulation of the argument orderLength results in heap-based buffer overflow.

This vulnerability is cataloged as CVE-2026-67298. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.