Security Advisory
CVE-2026-59851
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.