A parsing bug in OpenSSH affecting releases from the past 15 years (CVE-2026-35414, CVSS 8.1) allows a comma in a certificate principal to be treated as a list separator, enabling access control bypass and authentication as root when a valid certificate from a trusted CA is presented. Cyera reported the issue and said attacks cannot be detected via log-based detection; OpenSSH fixed the flaw in version 10.3 released in early April and organizations are advised to audit and update.
Part of the PlainSec briefing for 2026-04-27