HIGHVulnerability

CVE-2026-59851

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.

Properties

severity
HIGH
score
8.8
cve_id
CVE-2026-59851
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-07-21T15:16:37.897
last_modified
2026-08-17T22:17:15.903

Related Entities (5)

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (3)

[Product]
[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-59851 — Ninja Signal Threat Intelligence | Ninja Signal