Description
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in libssh results in the gssapi-keyex path not verifying whether the authenticated Kerberos principal is authorized for the requested local user. This omission allows an attacker who has established Kerberos authentication to log in as any local user, effectively bypassing the intended access controls. The weakness is an example of improper authorization (CWE‑863) and can enable unauthorized access on affected systems.

Affected Systems

The vulnerability affects Red Hat Enterprise Linux releases 8, 9 and 10, as well as Red Hat Hardened Images that ship with the libssh implementation. The specific fix or update is not detailed, so all consuming installations of libssh on these platforms are potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.8 classifies this as high severity, but the EPSS score of less than 1% indicates that the probability of exploitation in the wild is currently low. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly–known exploitation has been observed. Exploitation requires the server to have the GSSAPIKeyExchange feature enabled and the attacker must be able to authenticate via Kerberos, after which they can simply request a different local username to gain unauthorized access.

Generated by OpenCVE AI on July 30, 2026 at 17:25 UTC.

Remediation

Vendor Workaround

Disable GSSAPIKeyExchange.


OpenCVE Recommended Actions

  • Disable GSSAPIKeyExchange on all affected hosts
  • Monitor Red Hat errata for an update that patches libssh and apply the fix as soon as it becomes available
  • Enforce strict Kerberos principal to local user mapping, ensuring that only authorized principals are allowed to bind to local accounts

Generated by OpenCVE AI on July 30, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Libssh
Libssh libssh
Redhat hardened Images
Vendors & Products Libssh
Libssh libssh
Redhat hardened Images

Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
References

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 21 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
Title Libssh: libssh: authentication bypass via missing gssapi principal check
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-863
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Libssh Libssh
Redhat Enterprise Linux Hardened Images Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-22T19:06:52.468Z

Reserved: 2026-07-07T15:40:24.561Z

Link: CVE-2026-59851

cve-icon Vulnrichment

Updated: 2026-07-22T18:15:40.738Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T14:14:14Z

Links: CVE-2026-59851 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses