CVE-2026-35414Disclosure(openbsd / openssh)

MEDIUMCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openbsd openssh systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-670

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssh

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 21 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 13 signals
  • Disclosure: 7 classified signals
  • General: 7 classified signals
  • Peaked 7d ago at 5 mentions (2026-04-28); latest day: 1
  • 21 total mentions across 11 days

Affected systems

Vendors
Products
openssh

Deep dive

Activity timeline21 mentions / 11d
01345Mentions · 2026-04-02: 1Mentions · 2026-04-03: 2Mentions · 2026-04-27: 3Mentions · 2026-04-28: 5Mentions · 2026-04-29: 2Mentions · 2026-05-02: 1Mentions · 2026-05-04: 2Mentions · 2026-05-06: 1Mentions · 2026-05-13: 2Mentions · 2026-05-18: 1Mentions · 2026-06-04: 1PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-05-02: 1Exploit Tool / Code · 2026-04-28: 1Patch / Workaround · 2026-04-03: 2Patch / Workaround · 2026-04-27: 2Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-04-29: 2Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-06-04: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-28: 4Technical Details · 2026-04-29: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-13: 1Technical Details · 2026-06-04: 104-0204-0304-2704-2804-2905-0205-0405-0605-1305-1806-04
Signal classification4 categories
Disclosure
733.3%
General
733.3%
Patch
628.6%
PoC
14.8%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-04-032
Disclosure2
2026-04-273
General1Patch2
2026-04-285
Disclosure3General1Patch1
2026-04-292
Patch1PoC1
2026-05-021
Patch1
2026-05-042
General2
2026-05-061
Disclosure1
2026-05-132
General2
2026-05-181
General1
2026-06-041
Patch1
Full discourse20 posts
  • CCB Alert@CCBalert
    Patch

    Warning: #AuthenticationBypass #vulnerability in #OpenSSH. #CVE-2026-35414 CVSS: 8.1. This vulnerability grants full #root access! Read our advisory at https://ccb.belgium.be/advisories/warning-openssh-root-access-vulnerability-cve-2026-35414-patch-immediately and #Patch #Patch #Patch

    Post summary

    An advisory for CVE‑2026‑35414 in OpenSSH warns of an authentication bypass that permits full root access and urges immediate patching.

    02012289
    7.2K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-26268 2 - CVE-2026-27978 3 - CVE-2026-31431 4 - CVE-2026-33825 5 - CVE-2026-35414 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVE identifiers as trending topics but gives no additional information about exploitation, patches, or technical specifics.

    00030187
    1.7K followersView on X
  • DLTA@DLTA_Sec
    General

    Meanwhile, the infrastructure those agents operate on carries vulnerabilities older than most Web3 protocols. CVE-2026-35414 sat in OpenSSH for 15 years. Every bridge relay, RPC endpoint and validator node shipped with it.

    Post summary

    The post merely notes that CVE-2026-35414 has existed in OpenSSH for 15 years and is present in many related components, without providing further technical details or evidence of exploitation.

    2001072
    487 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    rootシェルアクセスに繋がり得るOpenSSHの脆弱性、15年にわたり発見されず(CVE-2026-35414) | Codebook https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45415/ "SSH証明書のプリンシパル名にカンマが含まれている場合にOpenSSHのアクセス制御がバイパスされ、ユーザーがrootとして認証することが可能になるとされる"

    Post summary

    The article announces the discovery of CVE-2026-35414, describing how a comma in an SSH certificate principal name can bypass OpenSSH access control and enable root authentication, with no evidence of active exploitation, patches, or PoC details.

    01011273
    3.5K followersView on X
  • Helios Mier@hmier
    General

    CVE-2026-35414 openSSH

    Post summary

    The post simply lists the CVE identifier for OpenSSH with no additional details.

    00030143
    1.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    A 15-year-old OpenSSH flaw (CVE-2026-35414) mishandles commas in certificate principals, granting full root shell access by bypassing log detection. Fixed in OpenSSH 10.3. #OpenSSHFlaw #RootAccess #USA https://ift.tt/5SKnOpV

    Post summary

    The tweet reports a long‑standing OpenSSH flaw that allows root access via malformed certificate principals and notes that a patch has been released in OpenSSH 10.3.

    01001158
    4.1K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 OpenSSH cert comma parsing bug (CVE-2026-35414) = even “mature” auth still trips on tiny text rules. For Windows admins: fix OpenSSH/Azure images or brace for weird access refusals. #Windows #Microsoft #OpenSSH #Security https://windowsforum.com/threads/cve-2026-35414-openssh-advisory-comma-parsing-risk-in-ssh-certificates.422519/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #OpensshSecurity #AzureLinux30 https://t.co/3RWtIontsY

    Post summary

    The tweet alerts Windows admins to an OpenSSH comma parsing bug in CVE‑2026‑35414 and urges them to update or patch Azure images to avoid login failures.

    0001056
    1.1K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    OpenSSH vulnerabilities CVE-2026-35385 & CVE-2026-35414 affect #openSUSE. Read more -> https://tinyurl.com/4vxdppw6 #Security https://t.co/RLvNLhUujm

    Post summary

    The post merely announces that OpenSSH bugs CVE-2026-35385 and CVE-2026-35414 affect openSUSE and directs readers to an external link for more information.

    1000056
    1.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: Most "AI agents" are just prompts duct-taped to APIs. CVE-2026-35414: OpenSSH Authentication Bypass — Lyrie's Autonomous Response Protocol in Production

    Post summary

    The post briefly cites CVE-2026-35414, an OpenSSH authentication bypass, but offers no exploitation details, patch information, or PoC, providing only a minimal mention of the vulnerability.

    1000046
    210 followersView on X
  • ますだまさる@m_masaru
    General

    @angel_p_57 RTの後に続けたから直接ツイートに出てきていませんが CAのパースで実装ミスった CVE-2026-35414 の話です

    Post summary

    The tweet references CVE‑2026‑35414 but provides no technical details, PoC, or exploitation context.

    1000078
    148 followersView on X
  • Michael Martino@battista212
    Disclosure

    OpenSSH vulnerability CVE-2026-35414 affects 15 years of versions, allows root shell via comma-separated cert principals. ADT breach hits 10M records. Trading Protocol loses $398k to missing auth check.

    Post summary

    The post announces the CVE-2026-35414 OpenSSH vulnerability, detailing its impact across 15 years of releases and its exploitation mechanism that can yield a root shell, but it contains no patch information, PoC, or evidence of active exploitation.

    1000056
    221 followersView on X
  • Machina Record@MachinaRecord
    Disclosure

    ⚠️rootシェルアクセスに繋がり得るOpenSSHの脆弱性、15年にわたり発見されず(CVE-2026-35414) 📱SMSブラスター装置が数千台の携帯電話を通信網から切断、緊急通報番号への発信も妨害 カナダ 〜サイバーアラート4月28日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45415/

    Post summary

    The alert announces the discovery of CVE‑2026‑35414, an OpenSSH vulnerability that may grant root shell access, with no PoC, exploit, or patch details provided.

    00010240
    1.3K followersView on X
  • Cyber Netsec IO@NetSecIO
    Patch

    🚨 CRITICAL: A 15-year-old flaw in OpenSSH (CVE-2026-35414) allows attackers to gain full root access. The bug is trivial to exploit and hard to detect in logs. Update to OpenSSH 10.3p1 immediately! 🛡️ #OpenSSH #CVE #Linux #CyberSecurity https://t.co/kZS70c34fh

    Post summary

    A critical OpenSSH flaw (CVE-2026-35414) that allows root access is announced with a call for immediate upgrade to OpenSSH 10.3p1.

    0100083
    44 followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    SIOSセキュリティブログを更新しました。 OpenSSHの脆弱性(High: CVE-2026-35385, Medium: CVE-2026-35414, Low: CVE-2026-35386, CVE-2026-35387, CVE-2026-35388)と10.3/10.3p1の公開 #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #openssh #ssh https://security.sios.jp/vulnerability/openssh-vulnerability-20260403/

    Post summary

    The blog post discloses new OpenSSH CVEs with their severity ratings and announces the release of patch versions 10.3/10.3p1.

    00010104
    361 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-35414-openssh-authentication-bypass-autonomous-response #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post points to a research article on CVE-2026-35414 but provides no actionable details about the vulnerability, exploitation, or remediation.

    0000031
    210 followersView on X
  • Vector_Signal@TheVectorSignal
    Disclosure

    OpenSSH CVE-2026-35414, publicly named “SplitSSHell,” shows how a small trust-logic bug can weaken remote administration. This is not a password attack or brute-force issue. It targets certificate-authentication logic inside trusted infrastructure. https://t.co/cVF3Gl3dTP

    Post summary

    The post announces the new OpenSSH CVE‑2026‑35414 (“SplitSSHell”), describing a trust‑logic flaw affecting certificate authentication, but does not share a PoC, exploit, evidence of active attacks, or a fix.

    0000059
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 Critical OpenSSH Authentication Bypass Vulnerability Grants Root Shell Access – Patch Immediately (#CVE-2026-35414) + Video https://undercodetesting.com/critical-openssh-authentication-bypass-vulnerability-grants-root-shell-access-patch-immediately-cve-2026-35414-video/ Educational Purposes!

    Post summary

    The post advertises a critical OpenSSH authentication bypass (CVE‑2026‑35414), includes a video demonstration, and highlights the need for immediate patching, but provides no exploitation details or active threat evidence.

    0000057
    520 followersView on X
  • ThreatCluster@threatcluster
    PoC

    BREAKING: PoC for OpenSSH CVE-2026-35414 drops as Ubuntu 26.04, 25.10, 24.04 LTS, 22.04 LTS rush patches for multiple OpenSSH bugs enabling code execution and priv-esc. https://threatcluster.io/cluster/critical-openssh-vulnerabilities-affecting-multiple-ubuntu-v-802294bb

    Post summary

    A proof‑of‑concept for CVE‑2026‑35414 has been released, prompting Ubuntu to push urgent patches for several OpenSSH vulnerabilities that could allow code execution and privilege escalation.

    00000102
    170 followersView on X
  • st8le̤̤̤̤̤̤̤̤̤̤ss@st8less
    Patch

    OpenSSH CVE-2026-35414: A comma in an SSH certificate principal name leads to OpenSSH access control bypass, allowing users to authenticate as root on a vulnerable server, as long as they have a valid certificate from a trusted CA. Patched early in April w/ version 10.3 https://www.securityweek.com/openssh-flaw-allowing-full-root-shell-access-lurked-for-15-years/

    Post summary

    The post reports that CVE-2026-35414 in OpenSSH allows root access via a comma in certificate principals and that the flaw has been fixed with version 10.3 released in early April.

    00000142
    378 followersView on X
  • IT関連サイト記事@itit7777
    Disclosure

    IT関連サイト記事が更新されました!記事はこちらから⇒ OpenSSHの脆弱性(High: CVE-2026-35385, Medium: CVE-2026-35414, Low: CVE-2026-35386, CVE-2026-35387, CVE-2026-35388)と、OpenSSH 10.3/10.3p1の公開 https://security.sios.jp/vulnerability/openssh-vulnerability-20260403/

    Post summary

    The article announces the discovery of several OpenSSH vulnerabilities and the release of new versions (10.3/10.3p1) that presumably address them.

    0000052
    446 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbsdopenssh---

Explore more