CVE-2026-106553: Low severity OpenSSH OpenSSH vulnerability
Published Oct 6, 2026
·Updated
In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt.
Affected Software
1 affected component
OpenSSH OpenSSH<10.6
Event History
Oct 6, 2026
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and conditions are required to exploit this issue?
Exploitation requires local access, low privileges, high attack complexity, and user interaction. The issue is tied to a failed GSSAPIAuthentication attempt in sshd.
2
Which confidentiality, integrity, and availability impacts are indicated?
The supplied severity vector indicates low confidentiality impact, with no integrity or availability impact.
3
What versions should be updated?
OpenSSH versions before 10.6 are affected according to the available information. Updating to OpenSSH 10.6 or later addresses the affected version range.