CVE-2026-35414 is a medium-severity vulnerability affecting OpenSSH versions prior to 10.3, stemming from improper handling of the `authorized_keys` `principals` option in specific scenarios involving comma characters within a principals list used with a Certificate Authority. With a CVSS score of 5.4, it has a low attack complexity and requires low privileges, potentially leading to low impacts on confidentiality and integrity, but no impact on availability. There is no known active exploitation, public exploit code, or inclusion in CISA's KEV catalog, and its EPSS score is extremely low. While community discussion is minimal, it was noted alongside the release of OpenSSH 10.3, which likely contains the fix.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.3CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | ||
>= 0, < 10.3CPE match | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenSSH vulnerability
Jul 21, 2026OpenSSH vulnerabilities
Apr 29, 2026OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
Apr 2, 2026