๐Ÿ” CVE Alert

CVE-2026-83540

UNKNOWN 0.0

wolfSSHd on Windows race condition leading to logon token reused across connections

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.

CWE CWE-287 CWE-613
Vendor wolfssl
Product wolfssh
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for wolfssl wolfssh

Be the first to know when new unknown vulnerabilities affecting wolfssl wolfssh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

wolfSSL / wolfSSH
1.4.15 โ‰ค 1.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wolfSSL/wolfssh github.com: https://github.com/wolfSSL/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9 github.com: https://github.com/wolfSSL/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a wolfssl.com: https://www.wolfssl.com/docs/security-vulnerabilities/

Credits

Found by internal wolfSSL testing