GSSAPIAuthentication Flaw in OpenSSH
CVE-2026-106553

2.2LOW

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106553?

A vulnerability in OpenSSH affects all versions prior to 10.6, where credentials may erroneously remain stored after a failed GSSAPIAuthentication attempt. This flaw could expose sensitive information, potentially allowing unauthorized access if exploited. Users are recommended to update to the latest version to mitigate this risk and enhance overall security.

Affected Version(s)

OpenSSH 0 < 10.6

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.