CVE-2026-83540: fallo de gravedad alta en wolfSSL wolfSSH
wolfSSHd on Windows race condition leading to logon token reused across connections
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.7epss 0.3%
probabilidad de explotación
0.3%top 75% de las CVE
explotación observada
noninguna fuente lo reporta
When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
wolfSSL · wolfSSHCVEs relacionadas — wolfSSL wolfSSH
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-14942CRITICALAuthentication BypassEPSS 0.5%CVE-2025-11625CRITICALHost verification bypass and credential leakEPSS 0.4%CVE-2025-15382MEDIUMClient SCP Request Triggers Buffer Overread by 1 ByteEPSS 0.4%CVE-2026-0930LOWPotential wolfSSHd Buffer out-of-bounds Read on Windows Handling Terminal ResizeEPSS 0.2%