Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2791 articles · 163917 vulns · 37/41 feeds (7d)
← Back to list
4.2
CVE-2026-35414EXPLOITEDPATCHED
openbsd · openssh

CVE-2026-35414: OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list i

Description

ssh(1): validation of shell metacharacters in user names supplied on the command-line was performed too late to prevent some situations where they could be expanded from %-tokens in ssh_config. For certain configurations, such as those that use a "%u" token in a "Match exec" block, an attacker who can control the user name passed to ssh(1) could potentially execute arbitrary shell commands.

Affected Products

VendorProductVersions
openbsdopenssh0, < 10.3

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmqradar siemcert_advisory90%
open sourceopensshcert_advisory90%

References

  • https://www.openssh.org/releasenotes.html#10.3p1
  • https://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2
  • https://www.openwall.com/lists/oss-security/2026/04/02/3

Related News (10 articles)

Tier B
BSI Advisories21d ago
[NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Help Net Security30d ago
Debian 13.5 point release lands with security fixes, bug patches
→ No new info (linked only)
Tier D
SecurityWeek50d ago
OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years
→ No new info (linked only)
Tier B
BSI Advisories70d ago
[NEU] [mittel] OpenSSH: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security71d ago
Re: Announce: OpenSSH 10.3 released
→ No new info (linked only)
Tier A
Microsoft MSRC72d ago
CVE-2026-35414
→ No new info (linked only)
Tier C
oss-security74d ago
Re: Announce: OpenSSH 10.3 released
→ No new info (linked only)
Tier C
oss-security74d ago
Re: Announce: OpenSSH 10.3 released
→ No new info (linked only)
Tier C
oss-security74d ago
Re: Announce: OpenSSH 10.3 released
→ No new info (linked only)
Tier C
VulDB75d ago
CVE-2026-35414 | OpenSSH up to 10.2 Certificate authorized_keys control flow
→ No new info (linked only)
CVSS 3.14.2 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
10.3
CWECWE-670, CWE-78, CWE-20
PublishedApr 2, 2026
Last enriched50d agov5
Tags
command-injectionsshmetacharacter-bypasssecurity-fixuser-authenticationshell-injectionaccess-control-bypasscertificate-issues
Trending Score3
Source articles10
Independent6
Info Completeness11/14
Missing: epss, kev, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-55706
CVE-2026-55706: sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values f
Trending: 36
HIGHPRE-CVE
OpenBSD sppp_pap_input PAP Authentication Bypass Vulnerability
Trending: 26
HIGHCVE-2026-35385
CVE-2026-35385: In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' e
Trending: 6
LOWCVE-2026-35388
CVE-2026-35388: OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
Trending: 4
LOWCVE-2026-35386EXP
CVE-2026-35386: In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This r
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 2, 2026
Discovered by ZDM
Apr 2, 2026
Updated: affectedVersions, severity, activelyExploited
Apr 2, 2026
Actively Exploited
Apr 2, 2026
Exploit Available
Apr 2, 2026
Patch Available
Apr 2, 2026
Updated: description, tags
Apr 3, 2026
Updated: description, cweIds, tags
Apr 6, 2026
Updated: tags
Apr 27, 2026

Version History

v5
Last enriched 50d ago
v5Tier D50d ago

Updated description with detailed technical information, changed severity to HIGH, and updated CVSS score to 8.1.

tags
via SecurityWeek
v4Tier C71d ago

Updated description with new details about shell metacharacter validation and added CWE-20 and new tag 'shell-injection'.

descriptioncweIdstags
via oss-security
v3Tier C74d ago

Updated description with significant technical details about the handling of empty principals in certificates and added new tags related to security fixes.

descriptiontags
via oss-security
v2Tier C75d ago

Updated affected versions to include 10.2, changed severity to HIGH, and noted that the vulnerability is actively exploited.

affectedVersionsseverityactivelyExploited
via VulDB
v175d ago

Initial creation