CVE-2026-48851
Published May 25, 2026
·Updated
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
Affected Software
1 affected component
Putty PuTTY>=0.77<0.84
Event History
May 25, 2026
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-48851?
The severity of CVE-2026-48851 is classified as low with a score of 3.1.
2
What software is affected by CVE-2026-48851?
CVE-2026-48851 affects PuTTY versions 0.77 before 0.84.
3
How does CVE-2026-48851 impact TELNET sessions?
CVE-2026-48851 may falsely indicate trust status for TELNET data due to not clearing the trust status between proxy authentication and the main session.
4
What is the risk associated with CVE-2026-48851?
CVE-2026-48851 has a risk level rated at 17.
5
How can I mitigate the risk of CVE-2026-48851?
To mitigate CVE-2026-48851, users should upgrade to PuTTY version 0.84 or later.