Overview
What is CVE-2026-35414?
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
Vulnerability intelligence
CVE-2026-35414 and is rated High severity with a CVSS score of 8.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.