Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59851

Опубликовано: 21 июл. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.

Меры по смягчению последствий

Disable GSSAPIKeyExchange.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsshAffected
Red Hat Enterprise Linux 8libsshNot affected
Red Hat Enterprise Linux 9libsshNot affected
Red Hat Hardened Imageslibssh-main-0.12.1-4.hum1FixedRHSA-2026:4292221.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2498184libssh: libssh: authentication bypass via missing GSSAPI principal check

EPSS

Процентиль: 20%
0.00274
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
13 дней назад

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.

CVSS3: 8.8
nvd
13 дней назад

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.

CVSS3: 8.8
debian
13 дней назад

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, ...

CVSS3: 8.8
github
13 дней назад

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.

EPSS

Процентиль: 20%
0.00274
Низкий

8.8 High

CVSS3