Apache Kerby: Kerberos Pre-Authentication Bypass
Published Jun 26, 2026
7.3
HIGHCVSS 3.1
EPSS 0.53%
Description
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
Affected products
-
Affected
- ≥ 0, < 2.1.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache Kerby | unaffected | Affected
|
No data.
No data.
AMQ Clients 2026.Q3
kerb-server
Fixed · RHSA-2026:69459
Red Hat Data Grid 8
kerb-server
Not affected
Red Hat Data Grid 8
kerb-server-api-all
Not affected
Red Hat Fuse 7
kerb-server
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
kerb-server
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
kerb-server-api-all
Not affected
streams for Apache Kafka 2
kerb-server
Affected
streams for Apache Kafka 3
kerb-server
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| AMQ Clients 2026.Q3 | kerb-server | Fixed | RHSA-2026:69459 |
| Red Hat Data Grid 8 | kerb-server | Not affected | n/a |
| Red Hat Data Grid 8 | kerb-server-api-all | Not affected | n/a |
| Red Hat Fuse 7 | kerb-server | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | kerb-server | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | kerb-server-api-all | Not affected | n/a |
| streams for Apache Kafka 2 | kerb-server | Affected | n/a |
| streams for Apache Kafka 3 | kerb-server | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is an Important flaw in Apache Kerby, affecting Red Hat products that utilize Kerberos for authentication, including Red Hat AMQ, JBoss Data Grid, Enterprise Application Platform, and Red Hat JBoss Fuse. The vulnerability allows an attacker to bypass the Kerberos pre-authentication check by sending a specially crafted Pre-Authentication Data (PA-DATA) packet. This circumvents an initial authentication step, potentially leading to unauthorized access or impersonation within a Kerberos-protected environment.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- http://www.openwall.com/lists/oss-security/2026/06/26/8
- https://access.redhat.com/security/cve/CVE-2026-57915 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2493407 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39650 Advisory
- https://lists.apache.org/thread/1y3glgh3kzwoxo5m2lq504cjlh1dsrfh vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-57915
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57915.json
- https://www.cve.org/CVERecord?id=CVE-2026-57915
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data