Improper access control in libssh - CVE-2025-14821

 

Improper access control in libssh - CVE-2025-14821

Published: July 27, 2026


Vulnerability identifier: #VU139522
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14821
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to manipulate trusted SSH configuration and host key data to compromise connection security.

The vulnerability exists due to improper access control in the global configuration file loading behavior on Windows when loading configuration files and ssh_known_hosts from the C:\etc directory. A local user can create attacker-controlled files in that directory to manipulate trusted SSH configuration and host key data to compromise connection security.

This issue occurs when libssh is built with default configure options on Windows.


Affected software

libssh

How to mitigate CVE-2025-14821

Install security update from vendor's website.

libssh - addressed in versions 0.11.4, 0.12.0

External References

Related Security Bulletins