CVE-2026-83540

HIGH CVSS 4.0: 7.7 EPSS 0.34%
Updated Oct 07, 2026
Wolfssl
Parameter Value
CVSS 7.7 (HIGH)
Type CWE-613, CWE-287 (Improper Authentication)
Vendor Wolfssl
Public PoC No

When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0.

Non-Windows builds of wolfSSHd are not affected.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products

wolfssl:wolfssh