CVE-2026-59998
published 2026-07-08CVE-2026-59998: sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
PriorityP334medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.18%
7.6th percentile
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | openssh | < 10.4 | 10.4 |
| openbsd | openssh | — | — |
| ubuntu | openssh | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_ubuntu5.4MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2026-07-13·CVSS 5.4
CVE-2026-60001 [MEDIUM] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH sftp did not properly constrain the location
of downloaded files when connecting to an attacker-controlled server. An
attacker could possibly use this issue to write files to unintended
locations on the file system. (CVE-2026-59995)
It was discovered that OpenSSH scp could place files in the parent
directory of the intended destination when copying between two remote
hosts. An attacker could possibly use this issue to write files to
unintended locations. (CVE-2026-59996)
It was discovered that OpenSSH internal-sftp only recognized the first nine
command-line arguments, This could result in certain security-sensitive
arguments being ignored, contrary to expectations. (CV
Red Hat
openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory
vendor_redhat·2026-07-08·CVSS 4.8
CVE-2026-59998 [MEDIUM] CWE-909 openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory
openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory
A flaw was found in OpenSSH. The sshd component has an undocumented security-relevant behavior where GSSAPIStrictAcceptorCheck has no value when the server is in a Windows Active Directory environment. This could lead to unintended information disclosure and impact data integrity.
Package: openssh (Red Hat Enterprise Linux 10) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 6) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 7) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 8) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 9) - Fix deferred
Package: openssh (Red Hat Hardened Images) - Affected
Package: rhcos (Red Hat OpenShift Conta
VulDB
OpenBSD OpenSSH up to 10.3 privilege escalation
vuldb·2026-07-08·CVSS 4.8
CVE-2026-59998 [MEDIUM] OpenBSD OpenSSH up to 10.3 privilege escalation
A vulnerability was found in OpenBSD OpenSSH up to 10.3. It has been classified as problematic. This impacts an unknown function. This manipulation causes privilege escalation.
The identification of this vulnerability is CVE-2026-59998. The attack needs to be done within the local network. There is no exploit available.
GHSA
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
ghsa_unreviewed·2026-07-08
CVE-2026-59998 [MEDIUM] CWE-573 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
No detection rules found.
No public exploits indexed.
2026-07-08
Published