AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-31983

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

A missing authentication vulnerability in the SSH keys synchronization endpoint allows unauthenticated attackers to access sensitive information, including a list of users, their associated groups, and their public SSH keys. This exposure could facilitate further attacks, such as unauthorized access to systems using these keys. Organizations utilizing this endpoint should prioritize remediation to protect user data and maintain system integrity.

CVE
CVE-2026-31983
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%

Original NVD Description

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.

Related CVEs

Other vulnerabilities affecting the same vendor(s)