| Cyera Blog
ID: dec42448-7c4c-5d34-b98a-34b96f4563c9
STIX ID: report--dec42448-7c4c-5d34-b98a-34b96f4563c9
Feed Name: Cyera Blogs
**Critical OpenSSH certificate parsing vulnerability (CVE-2026-35414):** Cyera Research discovered a long-standing flaw where a crafted SSH certificate principal containing a comma can be interpreted as multiple principals by the cert-authority path in authorized_keys, allowing an attacker who obtains such a certificate to authenticate as unintended users (including root) on affected servers; the issue affects setups that use cert-authority entries in authorized_keys but not TrustedUserCAKeys, and it enables deterministic, single-connection exploitation with broad potential impact across bastions, CI/CD pipelines, and systems trusting the vulnerable CA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
