Authentication Bypass Flaw in libssh Affects Multiple Server Environments
CVE-2026-59851
8.8HIGH
What is CVE-2026-59851?
A security issue has been identified in libssh, specifically affecting servers with the GSSAPIKeyExchange feature enabled. The flaw occurs in the gssapi-keyex path, where it does not properly verify if the authenticated Kerberos principal is authorized to access the intended local user account. This vulnerability permits authenticated clients to log in as other users without proper authorization, potentially leading to unauthorized access and privilege escalation.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Aisle Research for reporting this issue.