Authentication Persistence Issue in OpenSSH
CVE-2026-106555

2.2LOW

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106555?

An issue has been identified in OpenSSH where the GSSAPIAuthentication state may be incorrectly retained across multiple authentication sessions. This flaw could potentially allow an unauthorized user to gain access by leveraging previously established authentication states, thereby undermining the security model of the application. Users are encouraged to update to OpenSSH version 10.6 or later to mitigate this risk. More details can be found in the official release notes.

Affected Version(s)

OpenSSH 0 < 10.6

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.