Authentication Persistence Issue in OpenSSH
CVE-2026-106555
2.2LOW
What is CVE-2026-106555?
An issue has been identified in OpenSSH where the GSSAPIAuthentication state may be incorrectly retained across multiple authentication sessions. This flaw could potentially allow an unauthorized user to gain access by leveraging previously established authentication states, thereby undermining the security model of the application. Users are encouraged to update to OpenSSH version 10.6 or later to mitigate this risk. More details can be found in the official release notes.
Affected Version(s)
OpenSSH 0 < 10.6