A severe, long-standing vulnerability has been discovered in OpenSSH, the ubiquitous tool for secure remote shell access. Tracked as CVE-2026-35414, the flaw is a privilege escalation vulnerability with a CVSS 8.1 score that has existed in the codebase for approximately 15 years. It allows a remote attacker with low-level, valid credentials (in the form of a certificate from a trusted CA) to gain full root shell access on a vulnerable server. The vulnerability stems from an incorrect code reuse error, where a function designed to parse comma-separated lists was improperly used to handle SSH certificate principal names. Exploitation is trivial and, critically, does not generate failed login attempts, making it exceptionally difficult to detect via standard log monitoring. The flaw is patched in OpenSSH version 10.3p1.
The vulnerability lies in the handling of the authorized_keys file's principals option when using SSH certificate-based authentication. The core issue is a logic flaw (CWE-670: Always-Incorrect Control Flow Implementation) where the code responsible for parsing principal names from a certificate incorrectly reuses a function meant for parsing comma-separated cipher lists.
Here's the attack process:
deploy,root.sshd daemon parses the principal field.sshd splits deploy,root at the comma, treating it as a list of two principals: deploy and root.authorized_keys file on the server is configured to trust the CA for the root user, the server will incorrectly grant the attacker a root shell, even if they were only authorized for the deploy principal.This constitutes a classic privilege escalation attack (T1068 - Exploitation for Privilege Escalation). The exploit is simple to execute once the prerequisites are met and provides the highest level of access to the target system.
Security firm Cyera, which discovered the flaw, confirmed they developed a working exploit in under 20 minutes. While there is no public evidence of in-the-wild exploitation at this time, the simplicity of the exploit means that threat actors will likely develop and deploy it quickly. The fact that exploitation is stealthy (not logged as a failure) makes it an attractive target for attackers.
The impact is critical. Gaining full root access on a server allows an attacker to do anything: steal, modify, or delete all data; install persistent backdoors or ransomware; disable security controls; and use the compromised machine as a pivot point to attack other systems on the network. Given that OpenSSH is a foundational component of countless servers across all industries, the potential scope of this vulnerability is massive.
The following patterns may help identify vulnerable or compromised systems:
/etc/ssh/sshd_configTrustedUserCAKeys directives to identify servers using certificate-based authentication.~/.ssh/authorized_keysauthorized_keys files, especially for the root user, for principals= clauses and cert-authority directives.SSH authentication logsPrincipal name with commaDetecting exploitation post-facto is extremely difficult due to the lack of failure logs. Proactive detection is key.
10.3 should be flagged as critical.sshd_config and authorized_keys files across your fleet to identify servers configured for certificate authentication. Prioritize these systems for patching.System File Analysis (D3-SFA) to monitor for unauthorized changes to authorized_keys files.principals restriction to the authorized_keys file for critical accounts like root. For example, adding principals="root" to the root user's authorized_keys entry for a given CA key will explicitly limit it to only accept certificates with the root principal.Application Configuration Hardening (D3-ACH).The 15-year-old OpenSSH flaw, CVE-2026-35414, has been dubbed 'SplitSSHell', with new reports reiterating its critical impact.
The critical 15-year-old OpenSSH vulnerability, CVE-2026-35414, has now been formally named 'SplitSSHell'. New reports continue to emphasize the severe impact of this flaw, which allows an authenticated attacker to gain stealthy root access via specially crafted SSH certificates. Organizations are strongly urged to update to OpenSSH 10.3 or newer immediately to mitigate this high-severity threat. The core exploitation mechanism and its implications remain consistent with initial disclosures.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.