Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4989 articles · 189008 vulns · 37/41 feeds (7d)
← Back to list
7.3
CVE-2026-57915PATCHED
apache · kerby

Apache Kerby: Kerberos Pre-Authentication Bypass

Description

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

Affected Products

VendorProductVersions
apachekerby0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibminfosphere informationcert_advisory90%

References

  • https://lists.apache.org/thread/1y3glgh3kzwoxo5m2lq504cjlh1dsrfh(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories7h ago
[NEU] [hoch] IBM InfoSphere Information Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security47d ago
CVE-2026-57915: Apache Kerby: Kerberos Pre-Authentication Bypass
→ No new info (linked only)
Tier C
VulDB47d ago
CVE-2026-57915 | Apache Kerby up to 2.1.1 Kerberos improper authentication
→ No new info (linked only)
CVSS 3.17.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.1.2
CWECWE-304
PublishedJun 26, 2026
Last enriched47d agov2
Trending Score51
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-49975EXP
Apache HTTP Server: mod_http2 denial of service
Trending: 86
MEDIUMCVE-2026-57914EXP
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
Trending: 56
CRITICALCVE-2026-34191
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Trending: 43
HIGHCVE-2026-55969
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Trending: 42
HIGHCVE-2025-49506
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Trending: 37

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Updated: affectedVersions
Jun 26, 2026
Patch Available
Aug 3, 2026

Version History

v2
Last enriched 47d ago
v2Tier C47d ago

Updated severity to CRITICAL, added affected version 2.1.1, and marked the vulnerability as actively exploited.

affectedVersions
via VulDB
v147d ago

Initial creation