{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/libssh/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":3.7,"id":"CVE-2026-59842"},{"cvss":6.5,"id":"CVE-2026-59843"},{"cvss":6.5,"id":"CVE-2026-59844"},{"cvss":5.3,"id":"CVE-2026-59845"},{"cvss":3.9,"id":"CVE-2026-59846"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libssh","libssh \u003c 0.12.1","libssh \u003c 0.11.5"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authorization-bypass","privilege-escalation","libssh"],"_cs_type":"threat","_cs_vendors":["libssh project","libssh"],"content_html":"\u003cp\u003eCVE-2026-59851 describes a critical authorization bypass vulnerability within the libssh library when configured on servers with GSSAPIKeyExchange enabled. This flaw resides specifically in the \u003ccode\u003egssapi-keyex\u003c/code\u003e path, where the library fails to properly verify if an already authenticated Kerberos principal is authorized to log in as the requested local user. This allows an attacker, who has successfully authenticated via Kerberos, to potentially assume the identity of any arbitrary local user on the system, including privileged accounts, leading to unauthorized access and privilege escalation. While no specific threat actor or active exploitation campaigns have been detailed in the NVD source, the high CVSS score of 8.8 indicates a severe risk. Defenders should prioritize patching and configuration review to mitigate this risk, as successful exploitation could grant full control over affected systems.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains valid Kerberos credentials for an account within the target network environment.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates an SSH connection to a server running a vulnerable version of libssh with GSSAPIKeyExchange explicitly enabled.\u003c/li\u003e\n\u003cli\u003eDuring the SSH authentication process, the attacker leverages their Kerberos credentials via the GSSAPIKeyExchange mechanism.\u003c/li\u003e\n\u003cli\u003eThe vulnerable libssh server's \u003ccode\u003egssapi-keyex\u003c/code\u003e path processes the Kerberos authentication request.\u003c/li\u003e\n\u003cli\u003eDue to the flaw (CVE-2026-59851), the server incorrectly maps the authenticated Kerberos principal to an arbitrary local user specified by the attacker, bypassing proper authorization checks.\u003c/li\u003e\n\u003cli\u003eThe libssh server grants the attacker a session as the chosen arbitrary local user, potentially leading to privilege escalation if a privileged user (e.g., \u003ccode\u003eroot\u003c/code\u003e) is targeted.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-59851 allows an authenticated attacker to bypass intended authorization mechanisms and log in as any local user on the compromised server. This can lead to severe consequences, including unauthorized access to sensitive data, modification or deletion of system files, and complete system compromise, particularly if the attacker gains access as an administrative user. Organizations using libssh with GSSAPIKeyExchange enabled in environments with Kerberos authentication are at risk, and the impact could range from data exfiltration to total disruption of services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-59851 by updating all libssh installations to a fixed version immediately.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not feasible, review system configurations and disable \u003ccode\u003eGSSAPIKeyExchange\u003c/code\u003e on libssh servers unless absolutely necessary.\u003c/li\u003e\n\u003cli\u003eImplement robust monitoring of authentication logs for unusual login attempts or successful logins by Kerberos principals mapped to unexpected local user accounts, leveraging available log sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T17:15:59Z","date_published":"2026-07-21T15:21:32Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-59851-libssh-gssapikeyexchange-bypass/","summary":"A vulnerability in libssh, tracked as CVE-2026-59851, allows an authenticated Kerberos principal to bypass authorization checks on servers with GSSAPIKeyExchange enabled, enabling arbitrary local user login and potential privilege escalation.","title":"CVE-2026-59851: Libssh GSSAPIKeyExchange Authorization Bypass","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-59851-libssh-gssapikeyexchange-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Libssh","version":"https://jsonfeed.org/version/1.1"}