CVE-2026-59851
Red Hat Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
- CVSS
- 8.8
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.22