NONE · 0

CVE-2026-39828

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force...

Vulnerability Description

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.

References

FAQ

What is CVE-2026-39828?

CVE-2026-39828 is a documented vulnerability. When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force...

How severe is CVE-2026-39828?

CVSS scoring is not yet available for CVE-2026-39828. Check NVD for updates.

Is there a patch for CVE-2026-39828?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.