Executive brief
OpenSSH is a widely used tool for secure remote access to servers. A security-relevant behavior has been identified where a specific security setting, intended to strictly validate the identity of the server during login, is ignored when the server is part of a Windows Active Directory environment. This could potentially allow an attacker to bypass certain identity checks during the authentication process, though it requires specific environmental conditions to exploit.
Technical details
In OpenSSH versions prior to 10.4, the 'GSSAPIStrictAcceptorCheck' configuration option in sshd is ineffective when the host is joined to a Windows Active Directory environment. This option is intended to ensure that the GSSAPI acceptor name matches the server's actual hostname, preventing certain types of credential redirection or impersonation. The root cause is an undocumented behavior where the check is bypassed in AD environments. An attacker could potentially exploit this to use a service ticket intended for one host to authenticate to another, provided GSSAPI authentication is enabled. The issue is addressed in OpenSSH 10.4 by updating documentation and/or behavior to reflect this limitation.
Affected products
- OpenBSD OpenSSH before 10.4
Timeline
- 2026-07-06: patched: OpenSSH 10.4 released with fix/documentation update
- 2026-07-08: disclosed: CVE published to NVD