CyberRota
← Ana sayfaya dön

CVE-2026-39831

CRITICAL · CVSS 9.1 EPSS %0.31

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-22T04:16:22.553 · Çekilme zamanı: 2026-06-20T12:03:36.952643+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-39831
Severity
CRITICAL
CVSS
9.1
EPSS
%0.31

Orijinal NVD Açıklaması

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.