CVE-2026-35414: High severity OpenBSD OpenSSH vulnerability
Published Apr 2, 2026
·Updated
Last updated 10 July 2026
Other sources
OpenSSH before 10.3 mishandles the authorizedkeys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
— MITRE
Affected Software
7 affected componentsFixes available
OpenBSD OpenSSH<10.3
Microsoft azl3 openssh 9.8p1-6
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1
debian/openssh<=1:8.4p1-5+deb11u3, <=1:9.2p1-2+deb12u9, <=1:10.0p1-7+deb13u2
1:8.4p1-5+deb11u71:9.2p1-2+deb12u101:10.0p1-7+deb13u41:10.3p1-51:10.4p1-2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:8.4p1-5+deb11u7Fixed in 1:9.2p1-2+deb12u10Fixed in 1:10.0p1-7+deb13u4Fixed in 1:10.3p1-5Fixed in 1:10.4p1-2 - Upgrade
Upgrade
OpenSSHto a version that resolves this vulnerability.Fixed in 10.3
Event History
Apr 2, 2026
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 4, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:02 AM
Affected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Jul 22, 2026
Data Sourced
via Ubuntu·03:16 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·03:17 PM
DescriptionAffected Software
Data Sourced
via Launchpad·03:17 PM
Description