Apache Kerby Kerberos Pre-Auth Bypass, Pre v2.1.2 (PA-DATA)
CVE-2026-57915 Published on June 26, 2026

Apache Kerby: Kerberos Pre-Authentication Bypass
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-57915 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
LOW

Weakness Types

Missing Critical Step in Authentication

The software implements an authentication technique, but it skips a step that weakens the technique. Authentication techniques should follow the algorithms that define them exactly, otherwise authentication can be bypassed or more easily subjected to brute force attacks.

Improperly Implemented Security Check for Standard

The software does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.


Products Associated with CVE-2026-57915

Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.

 
 
 
 
 

Affected Versions

Apache Software Foundation Apache Kerby: Red Hat AMQ Clients: Red Hat JBoss Enterprise Application Platform Expansion Pack: Red Hat streams for Apache Kafka 2: Red Hat streams for Apache Kafka 3: Red Hat Data Grid 8: Red Hat Fuse 7: