CVE-2026-106555: Low severity OpenSSH OpenSSH vulnerability
Published Oct 6, 2026
·Updated
In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.
Affected Software
1 affected component
OpenSSH OpenSSH<10.6
Event History
Oct 6, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are in scope for this issue?
The issue affects sshd in OpenSSH versions before 10.6. It is specifically associated with GSSAPIAuthentication authentication state handling.
2
What would an attacker need to exploit it?
The supplied vector indicates local access, low privileges, high attack complexity, and user interaction are required. The vector does not indicate that remote unauthenticated exploitation is possible.
3
What is the expected security impact?
The reported impact is limited to low confidentiality impact. No integrity or availability impact is indicated.