CVE-2026-59998CWE-573
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory
Medium · published July 8, 2026
What it is
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
The record
Technical detail
- CVSS v3.1
- 4.8 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00180 · 7.6th percentile
- Weakness
- CWE-573 · Improper Following of Specification by Caller
- Published
- 2026-07-08T00:11Z
EPSS history
Timeline