User Login Poisoning Vulnerability in wolfSSHd on Windows by wolfSSL
CVE-2026-83540

7.7HIGH

Key Information:

Vendor

Wolfssl

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-83540?

The Windows version of wolfSSHd contains a vulnerability where the logon token for an authenticated connection is not properly released before a new connection attempts authentication. This oversight allows a less privileged user with valid account access to maliciously exploit the existing connection to force their login as a more privileged user. This flaw was introduced in wolfSSH version 1.4.15 and affects all versions up to 1.5.0 on Windows platforms, though non-Windows builds remain unaffected.

Affected Version(s)

wolfSSH Windows 1.4.15 <= 1.5.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found by internal wolfSSL testing
.