# OpenSSH Certificate Bug Enables Root Bypass

Published: 2026-04-28 · Severity: medium
Canonical: https://vorant.io/reports/13a97b65-fc3e-5590-ad05-b08769a91208/openssh-certificate-bug-enables-root-bypass

> A flaw in OpenSSH's handling of comma characters in certificate principals lets attackers with a trusted CA certificate authenticate as root.

CISA's MS-ISAC issued an advisory on CVE-2026-35414, a vulnerability in OpenSSH versions prior to 10.3 affecting how the authorized_keys principals option processes certificate principal names. When a Certificate Authority's certificate principal list contains comma characters in specific configurations, OpenSSH's access control logic can be bypassed, allowing an attacker holding a valid certificate from a trusted CA to authenticate as root on the affected server.

The issue was identified by researcher Cyera, who successfully demonstrated exploitation using a test certificate and test server, though there is no indication of active exploitation in the wild. Because OpenSSH is broadly deployed for remote administration across virtually all sectors, successful exploitation could grant an attacker root access to any server running the vulnerable configuration, making this a high-impact issue for environments relying on certificate-based SSH authentication with CA-signed principals.

Organizations running affected OpenSSH versions should prioritize patching to 10.3 or later, apply least-privilege principles to limit blast radius, and review CA-issued certificate principal configurations for unusual comma usage as a mitigating step pending patch deployment.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35414

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-openssh-could-allow-for-authentication-bypass_2026-040

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/13a97b65-fc3e-5590-ad05-b08769a91208/openssh-certificate-bug-enables-root-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
