Configuration in OpenSSH - CVE-2026-59998

 

Configuration in OpenSSH - CVE-2026-59998

Published: July 15, 2026


Vulnerability identifier: #VU137705
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59998
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The issue may allow a remote user to bypass implemented security restrictions.

The issue exists due to the the application has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. A remote user can bypass implemented security restriction. 


Affected software

OpenSSH
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openssh (Ubuntu package)
openssh-cavs-debuginfo
openssh-cavs
openssh-askpass-gnome-debugsource
openssh-askpass-gnome
openssh-askpass-gnome-debuginfo
openssh
openssh-server-debuginfo
openssh-common-debuginfo
openssh-server-config-disallow-rootlogin
openssh-clients
openssh-helpers
openssh-clients-debuginfo
openssh-fips
openssh-common
openssh-debuginfo
openssh-debugsource
openssh-helpers-debuginfo
openssh-server

How to mitigate CVE-2026-59998

Install updates from vendor's website.

OpenSSH - update to 10.4p1
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.16, 1:9.6p1-3ubuntu13.18, 1:10.2p1-2ubuntu3.4
openssh-cavs-debuginfo - update to 9.6p1-150600.6.49.1
openssh-cavs - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.49.1
openssh - update to 9.6p1-150600.6.49.1
openssh-server-debuginfo - update to 9.6p1-150600.6.49.1
openssh-common-debuginfo - update to 9.6p1-150600.6.49.1
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.49.1
openssh-clients - update to 9.6p1-150600.6.49.1
openssh-helpers - update to 9.6p1-150600.6.49.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.49.1
openssh-fips - update to 9.6p1-150600.6.49.1
openssh-common - update to 9.6p1-150600.6.49.1
openssh-debuginfo - update to 9.6p1-150600.6.49.1
openssh-debugsource - update to 9.6p1-150600.6.49.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.49.1
openssh-server - update to 9.6p1-150600.6.49.1

External References

Related Security Bulletins