| Cyera Blog
ID: dcc30cf4-5a90-5f80-ae76-c577e7b94011
STIX ID: report--dcc30cf4-5a90-5f80-ae76-c577e7b94011
Feed Name: Cyera Blogs
Cyera Research disclosed a critical OpenSSH vulnerability (CVE-2026-35414) in which a crafted SSH certificate with a comma-containing principal can bypass principal restrictions and authenticate as unintended users, including root, on servers that trust certificate authorities via cert-authority entries in authorized_keys. The flaw affects common deployments (bastion hosts, CI/CD, Vault/BLess workflows) and enables deterministic, single-connection exploitation across fleets, while TrustedUserCAKeys configurations are not affected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
