CVE-2026-59851

Published: July 22, 2026Last modified: July 28, 2026

Description

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.

Severity score breakdown

ParameterValue
Base score8.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Notes

Introduced in libssh-0.12.0 according to https://www.libssh.org/security/advisories/CVE-2026-59851.txt

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibsshNot affected (0.10.4-r0)
25 LTSlibsshNot affected (0.11.1-r0)
StreamlibsshFixed (0.12.1-r0)

References

ON THIS PAGE