THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-48859 (MEDIUM 5.3) — Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. When the SSH daemon is configured with the user_passwords or password option, ssh_

[NVD] CVE-2026-48859 (MEDIUM 5.3) — Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. When the SSH daemon is configured with the user_passwords or password option, ssh_

lownvdPublished 2026-06-10

CVE-2026-48859 CVSS: 5.3 MEDIUM Published: 2026-06-10T16:17:12.373

Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication.

When the SSH daemon is configured with the user_passwords or password option, ssh_auth:check_password/3 performs a PBKDF2-SHA256 compu

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48859