CyberRota Analysis
AI-GeneratedOpenSSH versions prior to 10.4 on Windows exhibit a security vulnerability where the GSSAPIStrictAcceptorCheck setting is ineffective when the server is part of an Active Directory environment. This could allow unauthorized access or man-in-the-middle attacks due to improper validation of server credentials. Organizations utilizing OpenSSH on Windows within Active Directory should prioritize patching to mitigate potential security risks.
CVE
CVE-2026-59998
Severity
MEDIUM
CVSS
4.8
EPSS
0.18%
Windows
Original NVD Description
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
Related CVEs
Other vulnerabilities affecting the same vendor(s)