Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Restrict which accounts may connect to the affected wolfSSHd instance on Windows hosts until the server is upgraded. Disabling public key authentication alone does not help, because password authentication is affected as well.
Wed, 07 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wolfssl
Wolfssl wolfssh |
|
| Vendors & Products |
Wolfssl
Wolfssl wolfssh |
Wed, 07 Oct 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected. | |
| Title | wolfSSHd on Windows race condition leading to logon token reused across connections | |
| Weaknesses | CWE-287 CWE-613 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: wolfSSL
Published:
Updated: 2026-10-07T11:29:08.132Z
Reserved: 2026-08-31T17:29:54.256Z
Link: CVE-2026-83540
Updated: 2026-10-07T11:29:02.152Z
Status : Received
Published: 2026-10-07T03:16:59.730
Modified: 2026-10-07T12:17:10.443
Link: CVE-2026-83540
No data.
OpenCVE Enrichment
Updated: 2026-10-07T04:45:12Z