CVE-2026-59851
Last modified
CVE-2026-59851 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libssh | Libssh | All versions |
| Redhat | Hardened Images | All versions |
| Redhat | Enterprise Linux | 10.0 |
References
- https://access.redhat.com/errata/RHSA-2026:42922Issue Tracking
- https://access.redhat.com/security/cve/CVE-2026-59851Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2498184Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-59851?
How severe is CVE-2026-59851?
How do I fix CVE-2026-59851?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59846A flaw was found in libssh. A malicious username expanded th…3.9
- CVE-2026-59847A flaw was found in libssh. Incorrect AES-GCM finalization c…7.5
- CVE-2026-59848A flaw was found in libssh. A malicious SFTP server can send…5.3
- CVE-2026-59849A flaw was found in libssh. Logic errors in automatic certif…7.5
- CVE-2026-5985A security flaw has been discovered in code-projects Simple …7.3
- CVE-2026-59850A flaw was found in libssh. If data packets are processed af…7.5
- CVE-2026-59853SiYuan is an open-source personal knowledge management syste…6.5
- CVE-2026-59854SiYuan is an open-source personal knowledge management syste…4.9
- CVE-2026-59855SiYuan is an open-source personal knowledge management syste…8.6
- CVE-2026-59856Vim is an open source, command line text editor. Prior to 9.…7.8
- CVE-2026-59857Vim is an open source, command line text editor. Prior to 9.…5.5
- CVE-2026-59858Vim is an open source, command line text editor. Prior to 9.…7.8
Are you affected by CVE-2026-59851?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
