Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-83540— wolfSSHd on Windows race condition leading to logon token reused across connections

Quick assessment

Affected
wolfSSL wolfSSH
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

当在 wolfSSHd 的 Windows 版本中使用密码或公钥认证时,在为一个已认证连接获取 Windows 登录令牌后,该令牌未能在获取后续连接的令牌之前被释放,从而导致连接之间的用户登录被污染(user login poisoning)。拥有服务器有效账户但权限较低的用户可利用此漏洞,强制以权限更高的用户身份进行登录。该漏洞由 wolfSSH 版本 1.4.15 中首次引入的 wolfSSHd Windows 端口带来,影响 1.4.15 至 1.5.0 的所有版本。wolfSSHd 的非 Windows 构

CVSS 7.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-83540

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wolfSSHd on Windows race condition leading to logon token reused across connections
Source: CVE Program / CVE List V5
Vulnerability Description
When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL wolfSSH 1.4.15 ~ 1.5.0 -

II. Public POCs for CVE-2026-83540

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-83540

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-83540 (2)

Vendor Pages for CVE-2026-83540 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-83540

No comments yet


Leave a comment