A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libssh | Jul 29, 2026 | Jul 21, 2026 |
| Redhat_linux | — | Upgrade libssh-develUpgrade libssh-debuginfoUpgrade libsshUpgrade libssh-debugsourceUpgrade libssh-config | Aug 19, 2026 | Jul 21, 2026 |
| Rocky_linux | — | Upgrade libssh-debugsourceUpgrade libsshUpgrade libssh-develUpgrade libssh-debuginfo | Aug 20, 2026 | Aug 18, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub