Description
When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.
Published: 2026-10-07
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Restrict which accounts may connect to the affected wolfSSHd instance on Windows hosts until the server is upgraded. Disabling public key authentication alone does not help, because password authentication is affected as well.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.
Title wolfSSHd on Windows race condition leading to logon token reused across connections
Weaknesses CWE-287
CWE-613
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wolfSSL

Published:

Updated: 2026-10-07T02:40:35.137Z

Reserved: 2026-08-31T17:29:54.256Z

Link: CVE-2026-83540

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T03:16:59.730

Modified: 2026-10-07T03:16:59.730

Link: CVE-2026-83540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses