← Vulnerability feed

Vulnerability record · CVE-2006-2369 · published 15 May 2006

CVE-2006-2369: RealVNC authentication bypass via insecure security type

Vnc · Realvnc

RealVNC 4.1.1 and products embedding it, including AdderLink IP and Cisco CallManager, accept a client-requested insecure security type such as "Type 1 - None" even when the server did not offer it. This lets a remote client skip authentication entirely, and the flaw was originally demonstrated using a long password. It matters because VNC provides direct interactive access to the desktop or console of the affected host.

7.5 CVSS 2.0 High EPSS 92% · top 0.2% CWE-287 · Improper authentication
7.5CVSS 2.0 base score
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
53References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote bypass of VNC authentication with a very high EPSS score and public exploit references, though no KEV listing or confirmed in-the-wild use is stated.

What it is

RealVNC 4.1.1 and products embedding it, including AdderLink IP and Cisco CallManager, accept a client-requested insecure security type such as "Type 1 - None" even when the server did not offer it. This lets a remote client skip authentication entirely, and the flaw was originally demonstrated using a long password. It matters because VNC provides direct interactive access to the desktop or console of the affected host.

Impact

An unauthenticated remote attacker gains interactive access to the VNC session, which typically means control of the desktop or console with the privileges of the logged-in user. The CVSS vector rates partial confidentiality, integrity and availability impact.

Attack surface

Reachable over the network on the VNC service port; no authentication is required because the bypass is the authentication step, and no user interaction is described. Any client able to reach the service can attempt the crafted security-type request.

Exploitation

Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.92355 (99.8th percentile) and multiple references carry Exploit tags, indicating public exploit material exists. The record does not state whether exploitation is observed in the wild.

What to do

  • Patch or upgrade RealVNC and any embedded RealVNC components (AdderLink IP, Cisco CallManager) per the vendor advisories referenced in the record.
  • Do not expose VNC services directly to untrusted networks; restrict access to management networks or VPN.
  • Enforce strong authentication at the network layer (for example SSH tunneling or a gateway) so a bypassed VNC authentication still faces a second control.
  • Where the product allows it, disable or refuse the "None" security type and require a strong authentication type.
  • Audit hosts for VNC listeners and confirm the running version is not a vulnerable RealVNC 4.1.1 build.

Detection

  • Monitor VNC service logs and network captures for security-type negotiation that selects "None" or Type 1 when the server did not offer it.
  • Alert on successful VNC sessions from unexpected source addresses or at unusual times, especially where no authentication event precedes them.
  • Inventory and version-scan hosts and embedded devices for RealVNC 4.1.1 or products known to embed it.
  • Correlate VNC connection events with subsequent interactive activity on the host to spot post-bypass access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=full-disclosure&m=114768344111131&w=2
http://marc.info/?l=vnc-list&m=114755444130188&w=2
http://seclists.org/fulldisclosure/2022/May/29
http://secunia.com/advisories/20107 PatchVendor Advisory
http://secunia.com/advisories/20109 PatchVendor Advisory
http://secunia.com/advisories/20789 Vendor Advisory
http://securityreason.com/securityalert/8355
http://securitytracker.com/id?1016083 ExploitPatch
http://www.cisco.com/warp/public/707/cisco-sr-20060622-cmm.shtml
http://www.intelliadmin.com/blog/2006/05/security-flaw-in-realvnc-411.html
http://www.intelliadmin.com/blog/2006/05/vnc-flaw-proof-of-concept.html ExploitPatch
http://www.kb.cert.org/vuls/id/117929 PatchThird Party AdvisoryUS Government Resource
http://www.osvdb.org/25479
http://www.realvnc.com/products/free/4.1/release-notes.html Patch
http://www.securityfocus.com/archive/1/433994/100/0/threaded
http://www.securityfocus.com/archive/1/434015/100/0/threaded
http://www.securityfocus.com/archive/1/434117/100/0/threaded
http://www.securityfocus.com/archive/1/434518/100/0/threaded
http://www.securityfocus.com/archive/1/434560/100/0/threaded
http://www.securityfocus.com/archive/1/438175/100/0/threaded
http://www.securityfocus.com/archive/1/438368/100/0/threaded
http://www.securityfocus.com/bid/17978 ExploitPatch
http://www.vupen.com/english/advisories/2006/1790 Vendor Advisory
http://www.vupen.com/english/advisories/2006/1821 Vendor Advisory
http://www.vupen.com/english/advisories/2006/2492 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/26445
http://marc.info/?l=full-disclosure&m=114768344111131&w=2
http://marc.info/?l=vnc-list&m=114755444130188&w=2
http://seclists.org/fulldisclosure/2022/May/29
http://secunia.com/advisories/20107 PatchVendor Advisory
http://secunia.com/advisories/20109 PatchVendor Advisory
http://secunia.com/advisories/20789 Vendor Advisory
http://securityreason.com/securityalert/8355
http://securitytracker.com/id?1016083 ExploitPatch
http://www.cisco.com/warp/public/707/cisco-sr-20060622-cmm.shtml
http://www.intelliadmin.com/blog/2006/05/security-flaw-in-realvnc-411.html
http://www.intelliadmin.com/blog/2006/05/vnc-flaw-proof-of-concept.html ExploitPatch
http://www.kb.cert.org/vuls/id/117929 PatchThird Party AdvisoryUS Government Resource
http://www.openwall.com/lists/oss-security/2024/08/02/8
http://www.osvdb.org/25479

Track CVE-2006-2369 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.0CVE-2004-1750Realvnc vulnerabilityRealVNC 4.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of connections to port 5900.EPSS 1.7%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.8CVE-2023-49105ownCloud Server WebDAV authentication bypass via pre-signed URLsownCloud core before 10.13.1 accepts pre-signed URLs even when the file owner has no signing-key configured, so the signature check is effectively sk…KEVEPSS 43%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed9.3CVE-2026-16232Check Point SmartConsole authentication bypass grants admin tokenCheck Point SmartConsole login contains an improper authentication flaw (CWE-287) that lets an unauthenticated remote attacker obtain an application …KEVEPSS 78%analysed

Source: NIST National Vulnerability Database (record CVE-2006-2369), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.