High severity7.3NVD Advisory· Published Jun 26, 2026· Updated Aug 3, 2026
CVE-2026-57915
CVE-2026-57915
Description
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
1- Apache Software Foundation: 21 Vulnerabilities Across Multiple Products Disclosed in Early July 2026Vypr Intelligence · Jul 3, 2026