CVE-2026-59851

EUVD-2026-46268
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 21.16%
Affected Products (NVD)
VendorProductVersion
libsshlibssh
-
redhathardened_images
-
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libssh
bookworm
0.10.6-0+deb12u2
fixed
bookworm (security)
0.10.6-0+deb12u1
fixed
bullseye
not-affected
forky
0.12.2-1
fixed
sid
0.12.2-1
fixed
trixie
0.11.2-1+deb13u1
fixed
trixie (security)
0.11.5-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libssh
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
not-affected
xenial
not-affected