Vulnerability record · CVE-2026-59851 · published 21 July 2026
CVE-2026-59851: Libssh incorrect authorization vulnerability
Libssh · Libssh
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
Description
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:42922 | Issue Tracking |
| https://access.redhat.com/errata/RHSA-2026:55855 | |
| https://access.redhat.com/security/cve/CVE-2026-59851 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2498184 | Issue TrackingVendor Advisory |
Track CVE-2026-59851 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-59851), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.