Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57915

Опубликовано: 26 июн. 2026
Источник: redhat
CVSS3: 7.3

Описание

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

A flaw was found in Apache Kerby. An attacker can bypass the Kerberos pre-authentication check by sending a Pre-Authentication Data (PA-DATA) packet with an unrecognized or unsupported type. This vulnerability allows an attacker to circumvent the initial authentication step, potentially leading to unauthorized access or impersonation within a Kerberos-protected environment.

Отчет

This is an Important flaw in Apache Kerby, affecting Red Hat products that utilize Kerberos for authentication, including Red Hat AMQ, JBoss Data Grid, Enterprise Application Platform, and Red Hat JBoss Fuse. The vulnerability allows an attacker to bypass the Kerberos pre-authentication check by sending a specially crafted Pre-Authentication Data (PA-DATA) packet. This circumvents an initial authentication step, potentially leading to unauthorized access or impersonation within a Kerberos-protected environment.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Clientskerb-serverAffected
Red Hat Data Grid 8kerb-serverNot affected
Red Hat Data Grid 8kerb-server-api-allNot affected
Red Hat Fuse 7kerb-serverNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkerb-serverNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkerb-server-api-allNot affected
streams for Apache Kafka 2kerb-serverAffected
streams for Apache Kafka 3kerb-serverAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=2493407Apache Kerby: org.apache.kerby/kerb-server: Apache Kerby: Kerberos pre-authentication bypass via unrecognized PA-DATA

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
около 1 месяца назад

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

CVSS3: 7.3
github
около 1 месяца назад

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

7.3 High

CVSS3