CVE-2026-59998
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.18%
- CWE
- CWE-573
- Published
- 2026-07-08
- Last modified
- 2026-07-08
Affected products
- OpenBSD OpenSSH
Weakness type
Related vulnerabilities
- CVE-2026-89087 — The cstruct package before 6.3.0 for OCaml mishandles indexes.
- CVE-2026-41583 — ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling
- CVE-2026-28498 — Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
- CVE-2025-69287 — BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability
- CVE-2025-69202 — axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
- CVE-2025-46330 — Snowflake Connector for C/C++ retries malformed requests
- CVE-2019-14829 — A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier...