CVE-2026-59998
Analyzed Analyzed - Analysis Complete

sshd GSSAPIStrictAcceptorCheck Missing in Windows AD

Vulnerability report for CVE-2026-59998, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-08

Last updated on: 2026-07-09

Assigner: MITRE

Description

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-08
Last Modified
2026-07-09
Generated
2026-07-11
AI Q&A
2026-07-08
EPSS Evaluated
2026-07-09
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openbsd openssh to 10.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-573 The product does not follow or incorrectly follows the specifications as required by the implementation language, environment, framework, protocol, or platform.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Compliance Impact

The provided information does not specify how the vulnerability in OpenSSH before 10.4 affects compliance with common standards and regulations such as GDPR or HIPAA.

Impact Analysis

This vulnerability can impact you by potentially weakening the security checks related to GSSAPI authentication when the OpenSSH server is integrated with Windows Active Directory. This could lead to a lower level of assurance in the authentication process, possibly allowing unauthorized access or impersonation under certain conditions.

Executive Summary

The vulnerability exists in sshd in OpenSSH versions before 10.4. It involves an undocumented security-relevant behavior where the configuration option GSSAPIStrictAcceptorCheck has no effect if the server is part of a Windows Active Directory environment.

Detection Guidance

The provided information does not include specific detection methods or commands to identify the vulnerability related to GSSAPIStrictAcceptorCheck in OpenSSH before version 10.4.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade your OpenSSH installation to version 10.4 or later, which includes fixes for issues related to GSSAPI authentication and other security improvements.

The update addresses the undocumented security-relevant behavior in sshd related to GSSAPIStrictAcceptorCheck when the server is in Windows Active Directory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59998. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart