CVE-2026-55706(openbsd / openbsd)

LOWCVSS 8.3 · HIGH

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openbsd

Affected systems

Vendors
Products
openbsd

Deep dive

Full discourse4 posts
  • Daily CyberSecurity@the_yellow_fall
    PoC

    A 27-year-old OpenBSD authentication bypass (CVE-2026-55706) is now public, with full details and a working PoC exploit for the PPP PAP flaw. #OpenBSD #AuthenticationBypass #PAP #PPPoE #InfoSec #CyberSecurity #Vulnerability #PoC https://securityonline.info/openbsd-pap-authentication-bypass https://t.co/d48T9U4eRV

    Post summary

    CVE-2026-55706 for OpenBSD PPP PAP authentication bypass has been publicly disclosed with full technical details and a working PoC exploit.

    01021465
    12.8K followersView on X
  • Mehrun@mehrrun
    General

    My two cents is that this democratises AI-availability and Privacy. Doom on hardware Y is an existence proof and dies there! For fulfilling your curiosity running a glm-5.1 UD-IQ1_M on one Mac studio M3 ultra plus a iogpu sysctl made us at #byteray #CVE-2026-55706 a 27-year old bug on #OpenBSD just a few weeks after Mythos worked heavily on the same part of the its kernel! Btw, it wasn’t just an llm prompt to hunt bugs, however a bit more work on agents, pairing 1bit quant with precomputed CPG/DFG analysis yet autonomously, RAG over mcp. The setup also leads us to hundreds of advisories including: #CVE-2026-55706 #CVE-2026-71967 #CVE-2026-71968 #CVE-2026-71969 #CVE-2026-71970 #CVE-2026-71971 #CVE-2026-71972 #CVE-2026-71973 #CVE-2026-71974 #CVE-2026-74220 #CVE-2026-74221 #CVE-2026-74222 #CVE-2026-74223 #CVE-2026-74224 #CVE-2026-74225 #CVE-2026-56099 #CVE-2026-56101 #CVE-2026-56102 #CVE-2026-56103 Yet all of these are just a small use case not a benchmark so I agree with you on that part @theByteRay

    Post summary

    The tweet lists several CVE identifiers discovered on OpenBSD but lacks concrete technical details, evidence of exploitation, or mitigation information.

    00010114
    267 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    OpenBSD の脆弱性 CVE-2026-55706 が FIX:27年前からの認証バイパスを発見 https://iototsecnews.jp/2026/06/17/27-year-old-openbsd-security-flaw-exposes-systems-to-full-pap-authentication-bypass/ この問題は、1999 年から残存していたレガシーコードに起因しています。同期 PPP 接続を処理する関数において、受信したパケットの長さ検証が不十分だったことが主な原因です。認証情報を比較する関数の特性により、攻撃者が長さを “0” として空の認証情報を送信すると、検証を行わずに認証が通過してしまいました。さらに、実際のバッファより大きな長さを指定された場合に、メモリの外側を読み取ってしまうヒープ・オーバーリードのリスクも抱えていました。このように、外部からの入力を適切に検証しない状態で処理してしまう実装が、深刻な認証バイパスを招く結果となっています。ご利用のチームは、ご注意ください。 #CVE202655706 #OpenBSD #Vulnerability

    Post summary

    The post discloses an 27‑year‑old authentication bypass flaw in OpenBSD’s PPP handling code, detailing its mechanics but providing no evidence of exploitation or explicit patch guidance.

    00000124
    499 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting OpenBSD (CVE-2026-55706) https://vuldb.com/vuln/371566/cti

    Post summary

    The post highlights identified offensive activity targeting OpenBSD related to CVE-2026-55706, suggesting the vulnerability is currently being exploited, though no technical or mitigation details are included.

    0000073
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSopenbsdopenbsd---

Explore more