Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.7
CVE-2026-83540: wolfSSHd on Windows lets lower‑privilege user log in as admin
CVE-2026-83540 · published 3 days ago
Summary
The Windows version of wolfSSHd (versions 1.4.15 through 1.5.0) can reuse a Windows login token from one connection for the next connection. This allows someone with a normal account to gain the rights of a more privileged account. Upgrade to a patched version of wolfSSHd or apply the vendor’s update to stop the token reuse.
What to do
- Update wolfssl wolfssh to version 1.6.0.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wolfssl | wolfssh |
<= 1.5.0 Fix: upgrade to 1.6.0
|
Original advisory text
wolfSSHd on Windows race condition leading to logon token reused across connections
When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.
References
- https://www.wolfssl.com/docs/security-vulnerabilities/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83540... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-83540 Vendor Advisory
- https://github.com/wolfSSL/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840...
- https://github.com/wolfSSL/wolfssh
- https://github.com/wolfSSL/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e...
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-287Improper Authentication
CWE-613Insufficient Session Expiration
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta