By weakness (CWE)
CWE-573: related vulnerabilities
CVEs classified under CWE-573. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
1 published vulnerability
- CVE-2026-59998MEDIUM 4.8
OpenSSH versions before 10.4 contain an undocumented security behavior where the GSSAPIStrictAcceptorCheck setting fails to function correctly when the SSH server is configured with Windows Active Directory authentication. This means servers relying on this setting for access control may not enforce the intended security checks, potentially allowing unauthorized access or credential exposure in Windows AD environments.