# ThinLinc 4.15.1 through 4.20.1 security release

**URL:** <https://community.thinlinc.com/t/thinlinc-4-15-1-through-4-20-1-security-release/1985>\
**Category:** Announcements\
**Tags:** security, thinlinc\
**Created:** [22 April 2026 12:03 UTC](https://community.thinlinc.com/t/thinlinc-4-15-1-through-4-20-1-security-release/1985 "2026-04-22T12:03:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![CendioOssman](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/cendioossman/32/385_2.png) [@CendioOssman](https://community.thinlinc.com/u/CendioOssman)\
**Post date:** [22 April 2026 12:03 UTC](https://community.thinlinc.com/t/thinlinc-4-15-1-through-4-20-1-security-release/1985/1 "2026-04-22T12:03:45Z")

</div>

A security release is now available that fixes a critical security issue in ThinLinc’s browser-based web client, Web Access. This release is available for all supported versions of ThinLinc, meaning ThinLinc 4.15.0 through 4.20.0. More details about the upgrade process can be found in this post:

[https://community.thinlinc.com/t/1983](https://community.thinlinc.com/t/1983)

The vulnerability allowed any user with access to the system to impersonate any other user, including the root user.

A multi-step authentication was required to exploit this vulnerability. E.g. one-time passwords, a login banner, or an expired password. A single-step username and password authentication was not sufficient to trigger the issue.

**If an upgrade is not immediately possible** , the vulnerability can be mitigated by disabling the ThinLinc Web Access service by running:

```console

$ sudo systemctl disable --now tlwebaccess.service

```

Until upgrading, the service should be disabled on all machines in the ThinLinc cluster.

The security release can be downloaded directly from our web page at:

> **[ThinLinc downloads | ThinLinc by Cendio](https://www.cendio.com/thinlinc/download/?for-administrators)**
>
> Download ThinLinc's client and server, the turn-key Linux terminal server built on open-source technology. Ideal for companies of all sizes.

This issue was discovered by our partner [Cosmikal S.L.](https://www.cosmikal.es/)

---

<div class="post-metadata">

**Author:** ![CendioOssman](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/cendioossman/32/385_2.png) [@CendioOssman](https://community.thinlinc.com/u/CendioOssman)\
**Post date:** [22 April 2026 12:05 UTC](https://community.thinlinc.com/t/thinlinc-4-15-1-through-4-20-1-security-release/1985/2 "2026-04-22T12:05:03Z")

</div>



---

<div class="post-metadata">

**Author:** ![CendioOssman](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/cendioossman/32/385_2.png) [@CendioOssman](https://community.thinlinc.com/u/CendioOssman)\
**Post date:** [23 April 2026 05:32 UTC](https://community.thinlinc.com/t/thinlinc-4-15-1-through-4-20-1-security-release/1985/3 "2026-04-23T05:32:16Z")

</div>

Details are now available on how to detect if this vulnerability has been exploited:

> [@Ruling out that the 2026-04-08 security issue was exploited](https://community.thinlinc.com/t/ruling-out-that-the-2026-04-08-security-issue-was-exploited/1986):
>
> This post provides guidance for verifying that the vulnerability discovered on 2026-04-08 has not been exploited on a ThinLinc cluster. See this announcement for more information and instructions for updating your ThinLinc installation: Note that we have not seen any indication that this vulnerability has been used by malicious actors in the wild. Directly ruling out exploitation If there have been no logins through Web Access, exploitation can be directly ruled out. This needs to be verifie…

---

<div class="post-metadata">

**Author:** ![wilsj](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/wilsj/32/554_2.png) [@wilsj](https://community.thinlinc.com/u/wilsj)\
**Post date:** [13 May 2026 09:19 UTC](https://community.thinlinc.com/t/thinlinc-4-15-1-through-4-20-1-security-release/1985/4 "2026-05-13T09:19:44Z")

</div>


