Junglewise Threat Intelligence

CVE-2026-48851: PuTTY trust sigil spoofing in Telnet and Rlogin sessions

CVE-2026-48851 · Severity: low · CVSS 3.1 · Published 2026-05-25

Technologies: Putty. Vendors: Putty.

Executive brief

PuTTY is a popular tool used to connect to remote servers. A security flaw exists where the application fails to clear a 'trust icon' (a small PuTTY logo) after a user finishes logging into a proxy server. This could allow a malicious server to trick a user into providing sensitive information, such as passwords, by making the server's fake prompts look like legitimate system messages from PuTTY itself.

Technical details

A vulnerability exists in PuTTY versions 0.77 through 0.83 due to improper state management of the 'trust sigil' (a UI indicator used to distinguish client-side prompts from server-sent data). When connecting via a proxy that requires authentication, PuTTY enables the trust sigil for its internal prompts but fails to clear this status before transitioning to the main Telnet or Rlogin session. An attacker controlling a malicious server or performing a Man-in-the-Middle (MITM) attack could exploit this by sending a spoofed password prompt immediately after proxy authentication. Because the trust sigil remains active, the user may be misled into believing the server's prompt is a legitimate request from the PuTTY client. This issue is addressed in version 0.84.

Affected products

  • PuTTY PuTTY 0.77 to 0.83

Timeline

  • 2026-05-22: patched: PuTTY 0.84 released with a fix.
  • 2026-05-25: disclosed: CVE-2026-48851 published.

References

Related threats