logo

27-Year-Old OpenBSD Authentication Bypass: Details and PoC Exploit Publicly Disclosed

ID: 2f7326d2-d226-5e7c-99d9-ff519ae495e9

STIX ID: report--2f7326d2-d226-5e7c-99d9-ff519ae495e9

Feed Name: securityonline.info

Threat Score
50/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Do Son

...
...

OpenBSD CVE-2026-55706 is a 27-year-old PAP authentication bypass in the sppp_pap_input() handler that lets an attacker on the same Layer 2 network (e.g., a rogue PPPoE server in the broadcast domain) authenticate without credentials by abusing length fields, and can additionally trigger a heap over-read; researchers published full technical details and a working PoC, and OpenBSD issued a patch (commit 076e2b1c1fc4ac0883a72d3544131ad5cee7adf8) — administrators using PAP over PPPoE should update promptly and treat Layer 2 segments as untrusted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.