CVE-2026-83540
wolfSSHd on Windows reuses logon token across connections
wolfSSH CVE-2026-83540 lets a user with a valid account on a Windows wolfSSHd server end up logged in as another, more privileged user, because the logon token was shared across concurrent connections. wolfSSL rates it High, CVSS 4.0 7.7. Fixed in wolfSSH 1.6.0. Not in CISA KEV. No public PoC.
- CVSS
- 7.7
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- Class
- Auth bypass
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- wolfSSL
- Products
- wolfSSH, wolfSSHd (Windows)
- Affected
- wolfSSHd on Windows, wolfSSH 1.4.15 through 1.5.0. Non-Windows builds of wolfSSHd are not affected.
- Fixed
- wolfSSH 1.6.0 or later.
- Published
- 7 Oct 2026
- Updated
- 8 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-83540 is a vulnerability in wolfSSH, wolfSSL's embedded SSH library, fixed in wolfSSH 1.6.0. wolfSSL published the 1.6.0 release on GitHub on 6 October 2026, and the CVE record was published on 7 October 2026. It lets a user with a valid account on a Windows wolfSSHd server end up logged in as another, more privileged user, because the logon token was shared across concurrent connections.
wolfSSL's advisory says wolfSSHd on Windows shared one authentication context, and the Windows logon token stored in it, across concurrent connections. Both password and public key logins wrote to that shared token. The CVE record describes it as a race condition: the token acquired for one authenticated connection is not released before a token is acquired for the next connection, which poisons logins between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user.
The attacker needs a valid account (CVSS PR:L), and the timing condition is reflected as AT:P. The flaw was introduced with the initial Windows port of wolfSSHd in 1.4.15. It affects only the Windows wolfSSHd server, not the wolfSSH library on other platforms.
wolfSSL rates the issue High. wolfSSL, acting as CNA, scores it CVSS 4.0 7.7 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N; NVD shows that score from wolfSSL and has not added its own analysis yet. CWE in the CNA record: CWE-287, CWE-613. Affected versions: wolfSSHd on Windows, wolfSSH 1.4.15 through 1.5.0. Non-Windows builds of wolfSSHd are not affected. The fix landed in PR #1163 and ships in 1.6.0. wolfSSL credits internal wolfSSL testing.
The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none (automatable: no). ThreatWire found no public proof-of-concept repository, and wolfSSL does not report exploitation. GitHub advisory GHSA-36jf-xmwg-5wp8 is unreviewed.
This is one of five wolfSSH CVEs fixed in 1.6.0: CVE-2026-16516 (Critical), CVE-2026-83540 (High), and CVE-2026-84897, CVE-2026-81535 and CVE-2026-83742 (Medium).