Executive brief
A security flaw in the libssh library allows an attacker who has already authenticated via Kerberos to log in as any other user on the system. This library is used to provide secure communication and remote access; an exploit could allow an attacker to gain unauthorized access to sensitive accounts or administrative privileges. This occurs on servers where GSSAPI Key Exchange is enabled, potentially leading to full system compromise.
Technical details
An authorization bypass exists in libssh's server-side GSSAPIKeyExchange implementation within `ssh_packet_userauth_request()` in `src/messages.c`. When `GSSAPIKeyExchange` is enabled, the `gssapi-keyex` authentication path grants access immediately after successful Kerberos authentication without executing the necessary callback to verify if the authenticated principal is authorized for the requested local username. A remote attacker with valid Kerberos credentials can exploit this to log in as any local user, including root, bypassing intended access controls. The vulnerability is tracked as CWE-863 (Incorrect Authorization).
Affected products
- libssh libssh unspecified
- Red Hat Red Hat Enterprise Linux 10 affected
- Red Hat Red Hat Hardened Images affected
Timeline
- 2026-07-08: other: Initial report in Red Hat Bugzilla
- 2026-07-21: disclosed: CVE published to NVD