CVE-2026-39828: CWE-863: Incorrect Authorization in golang.org/x/crypto golang.org/x/crypto/ssh
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.
AI Analysis
Technical Summary
The vulnerability arises when an SSH server using golang.org/x/crypto/ssh handles authentication callbacks that return PartialSuccessError along with non-nil Permissions. Instead of enforcing these permissions, the library silently discards them, which can result in bypassing certificate restrictions like force-command after successful second-factor authentication. This improper authorization handling (CWE-863) can lead to unauthorized command execution or access on affected systems. Red Hat's advisory confirms the issue affects their products using this library and notes no current mitigation or fix fully addresses the problem. The CVSS 3.1 base score is 6.3 (medium severity) with network attack vector, low complexity, low privileges required, no user interaction, and impacts confidentiality, integrity, and availability at a low level. No known exploits in the wild have been reported.
Potential Impact
This vulnerability can lead to unauthorized command execution or access by bypassing intended certificate restrictions such as force-command in SSH sessions. Systems that rely on multi-factor authentication and certificate-based access controls using golang.org/x/crypto/ssh are at risk. The impact affects confidentiality, integrity, and availability at a low level according to the CVSS score. No active exploitation has been reported, but the flaw could allow attackers to circumvent security controls after partial authentication success.
Mitigation Recommendations
According to the Red Hat advisory, no mitigation or fix currently meets their criteria for ease of use, deployment, applicability, or stability. Users should monitor vendor advisories for updates. Until an official fix is released, consider limiting exposure of affected SSH servers and reviewing authentication callback configurations to avoid returning PartialSuccessError with non-nil permissions if possible. Engage with Red Hat support or technical account managers for tailored guidance. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-39828: CWE-863: Incorrect Authorization in golang.org/x/crypto golang.org/x/crypto/ssh
Description
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.
CVSS v3.1
Score 6.3medium
Affected software
golang.org/x/crypto
golang.org/x/crypto/ssh
pkg:golang/golang.org/x/crypto/sshRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises when an SSH server using golang.org/x/crypto/ssh handles authentication callbacks that return PartialSuccessError along with non-nil Permissions. Instead of enforcing these permissions, the library silently discards them, which can result in bypassing certificate restrictions like force-command after successful second-factor authentication. This improper authorization handling (CWE-863) can lead to unauthorized command execution or access on affected systems. Red Hat's advisory confirms the issue affects their products using this library and notes no current mitigation or fix fully addresses the problem. The CVSS 3.1 base score is 6.3 (medium severity) with network attack vector, low complexity, low privileges required, no user interaction, and impacts confidentiality, integrity, and availability at a low level. No known exploits in the wild have been reported.
Potential Impact
This vulnerability can lead to unauthorized command execution or access by bypassing intended certificate restrictions such as force-command in SSH sessions. Systems that rely on multi-factor authentication and certificate-based access controls using golang.org/x/crypto/ssh are at risk. The impact affects confidentiality, integrity, and availability at a low level according to the CVSS score. No active exploitation has been reported, but the flaw could allow attackers to circumvent security controls after partial authentication success.
Mitigation Recommendations
According to the Red Hat advisory, no mitigation or fix currently meets their criteria for ease of use, deployment, applicability, or stability. Users should monitor vendor advisories for updates. Until an official fix is released, consider limiting exposure of affected SSH servers and reviewing authentication callback configurations to avoid returning PartialSuccessError with non-nil permissions if possible. Engage with Red Hat support or technical account managers for tailored guidance. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Go
- Date Reserved
- 2026-04-07T18:13:03.528Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-39828","vendor":"Red Hat"}]
Threat ID: 6a0fcdabe1370fbb487d4ffc
Added to database: 05/22/2026, 03:29:47 UTC
Last enriched: 08/13/2026, 13:01:45 UTC
Last updated: 09/11/2026, 22:23:26 UTC
Views: 112
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.