OpenSSH Certificate Bug Enables Root Bypass
A flaw in OpenSSH's handling of comma characters in certificate principals lets attackers with a trusted CA certificate authenticate as root.
CISA's MS-ISAC issued an advisory on CVE-2026-35414, a vulnerability in OpenSSH versions prior to 10.3 affecting how the authorized_keys principals option processes certificate principal names. When a Certificate Authority's certificate principal list contains comma characters in specific configurations, OpenSSH's access control logic can be bypassed, allowing an attacker holding a valid certificate from a trusted CA to authenticate as root on the affected server.
The issue was identified by researcher Cyera, who successfully demonstrated exploitation using a test certificate and test server, though there is no indication of active exploitation in the wild. Because OpenSSH is broadly deployed for remote administration across virtually all sectors, successful exploitation could grant an attacker root access to any server running the vulnerable configuration, making this a high-impact issue for environments relying on certificate-based SSH authentication with CA-signed principals.
Organizations running affected OpenSSH versions should prioritize patching to 10.3 or later, apply least-privilege principles to limit blast radius, and review CA-issued certificate principal configurations for unusual comma usage as a mitigating step pending patch deployment.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-openssh-could-allow-for-authentication-bypass_2026-040
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free