Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-41617

27
FAUCET Score

CVE-2021-41617 is a privilege escalation vulnerability in OpenSSH versions 6.2 through 8.x before 8.8, affecting products like Fedora, NetApp, and Oracle. When specific non-default configurations are used, helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand can execute with the elevated group privileges of the sshd process, even if configured to run as a different user. This vulnerability has a CVSS score of 7.0 (High), indicating a local attack vector with high complexity, leading to potential high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.2, < 8.8CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.54%
Probability of exploitation in next 30 days
EPSS Percentile
83.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0255 is in the 96th percentile among its peer group of 1,523 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

denopatch availablevia llm_extracted
View patch
keraspatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 16862-16820Fixed in: -
microsoftpatch availablevia msrc
Product: cm1 openssh 8.8p1-1 on CBL Mariner 1.0Fixed in: -
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssh-0:7.4p1-22.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssh-0:8.0p1-13.el8
View patch

Vendor Advisories (4)

denollm-deno-b67a3af2ce0be075CRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
kerasllm-keras-7d8c31fee70361dcCRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
redhatCVE-2021-41617Moderate

openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured

Sep 26, 2021
microsoft2021-Sep/CVE-2021-41617Important

sshd in OpenSSH 6.2 through 8.x before 8.8 when certain non-default configurations are used allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process if the configuration specifies running the command as a different user.

Sep 14, 2021

References

cert-portal.siemens.com / productcert/html/ssa-019113.html
cert-portal.siemens.com / productcert/html/ssa-082556.html
bugzilla.suse.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
lists.debian.org / debian-lts-announce/2023/12/msg00017.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KVI7RWM2JLNMWTOFK6BDUSGNOIPZYPUT
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/W44V2PFQH5YLRN6ZJTVRKAD7CU6CYYET
security.netapp.com / advisory/ntap-20211014-0004
Third Party Advisory
debian.org / security/2023/dsa-5586
openssh.com / security.html
Vendor Advisory
openssh.com / txt/release-8.8
Release NotesVendor Advisory
openwall.com / lists/oss-security/2021/09/26/1
Mailing ListThird Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
Third Party Advisory
starwindsoftware.com / security/sw-20220805-0001
Third Party Advisory
tenable.com / plugins/nessus/154174