{"id":"CVE-2026-83540","summary":"wolfSSHd on Windows race condition leading to logon token reused across connections","details":"When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.","modified":"2026-10-08T07:15:24.850610984Z","published":"2026-10-07T02:40:35.137Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.4.15"},{"fixed":"1.6.0"}]}],"cna_assigner":"wolfSSL","cwe_ids":["CWE-287","CWE-613"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83540.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83540.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83540"},{"type":"ADVISORY","url":"https://www.wolfssl.com/docs/security-vulnerabilities/"},{"type":"FIX","url":"https://github.com/wolfSSL/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a"},{"type":"FIX","url":"https://github.com/wolfSSL/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9"},{"type":"PACKAGE","url":"https://github.com/wolfSSL/wolfssh"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wolfssl/wolfssh","events":[{"introduced":"0"},{"fixed":"8643d7be841184f766374e3b0ed68ced6391543c"},{"fixed":"9777bc5ce810d6c418a1473e9e8c40cdb0026e5a"},{"fixed":"b6bd975ccfac6aadf29b98e35e09114bef3840a9"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.5.0"}]}}],"versions":["v1.4.22-stable","v1.4.21-stable","v1.4.20-stable","v1.4.19-stable","v1.4.18-stable","v1.4.17-stable","v1.4.15-stable","v1.4.16","v1.4.14-stable","v1.4.13-stable","v1.4.12-stable","v1.4.11-stable","v1.4.10-stable","v1.4.9","v1.4.8-stable","v1.4.7-stable","v1.4.6-stable","v1.4.5-stable","v1.4.4-stable","v1.4.3-stable","v1.4.2-stable","v1.4.0-stable","v1.3.0-stable","v1.2.2","v1.2.0-stable","v1.1.0-stable","v1.0.0-RC2","v1.0.0-RC1","v0.2.0","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83540.json","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/wolfssl/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a","target":{"file":"apps/wolfsshd/auth.c","function":"SetupUserTokenWin"},"deprecated":false,"digest":{"function_hash":"219644588490512202676991098277966226685","length":3700},"id":"CVE-2026-83540-2587992d","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/wolfssl/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a","target":{"file":"apps/wolfsshd/auth.c","function":"CheckPasswordWIN"},"deprecated":false,"digest":{"function_hash":"101779740054012997581232292582715593600","length":1888},"id":"CVE-2026-83540-289bd88a"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/wolfssl/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a","target":{"file":"apps/wolfsshd/auth.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["278773986947901878515219790257223463581","303781556256632243995204003066841843085","256111524276311919480060390374414168529","28222565115541727492706819136039558009","266428188333279143897189354987210236181","234838805002562847031532065622318811057","204218239792715954936718796067221095646"]},"id":"CVE-2026-83540-62113bd1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9","target":{"file":"apps/wolfsshd/auth.c","function":"wolfSSHD_AuthFreeUser"},"deprecated":false,"digest":{"function_hash":"198346462816318677227059521403127824871","length":313},"id":"CVE-2026-83540-6428cff6"},{"target":{"function":"SHELL_Subsystem","file":"apps/wolfsshd/wolfsshd.c"},"deprecated":false,"digest":{"length":7360,"function_hash":"108446564782534986208777503692222165383"},"id":"CVE-2026-83540-954d0daa","signature_type":"Function","signature_version":"v1","source":"https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9"},{"target":{"file":"apps/wolfsshd/auth.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["267992589283405772018351752202064813697","126107006151320590440788775643814235923","7808574815104365064046612331402168791","287874684528232171706906644882755874247"]},"id":"CVE-2026-83540-9a992ebd","signature_type":"Line","signature_version":"v1","source":"https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9"},{"source":"https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9","target":{"file":"apps/wolfsshd/auth.c"},"deprecated":false,"digest":{"line_hashes":["323882577220866782929120014764066400897","191965947403911647816825608152271133446","319641085095427172374837915482575675559","253169028308862144296152649432041788690","189029181797153464471304152879247416903","163960743321409786871494427534533470012","221186265729423297447196051941693262783"],"threshold":0.9},"id":"CVE-2026-83540-bb0971c8","signature_type":"Line","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9","target":{"file":"apps/wolfsshd/wolfsshd.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["175655273749361429960867408506612761527","70312326867526094872256596546303660217","116259992473061313384075712652551634912","149883931092474113103146305430090517258","26008619239679591543062581103702672971","290361149327050745936437531667357203783","65478345250581612689020163900172748975","116864508878598680653782173959734689359","169100608496135348544587699387752112047","61111332776651411365366949475486329137","335235687372992853316119545607377471266","268811912412110267696912500072565844297","36179908102983162681729614520121292227","322080785795647375807608710047498580050","327599562614879003477282633691107539088"]},"id":"CVE-2026-83540-ee4d5e2d"}],"vanir_signatures_modified":"2026-10-08T07:15:24Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}