CVE-2026-59851
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Jul 21, 2026
Vendor
unknown
Description
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.