Medium severity4.2NVD Advisory· Published Apr 2, 2026· Updated Apr 10, 2026
CVE-2026-35414
CVE-2026-35414
Description
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- marc.infonvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2026/04/02/3nvdThird Party Advisory
- www.openssh.org/releasenotes.htmlnvdRelease Notes
News mentions
1- CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)Rapid7 Blog · May 14, 2026