THREAT OPS › Threat News › [NVD] CVE-2026-48859 (MEDIUM 5.3) — Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication.
When the SSH daemon is configured with the user_passwords or password option, ssh_
[NVD] CVE-2026-48859 (MEDIUM 5.3) — Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. When the SSH daemon is configured with the user_passwords or password option, ssh_
CVE-2026-48859 CVSS: 5.3 MEDIUM Published: 2026-06-10T16:17:12.373
Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication.
When the SSH daemon is configured with the user_passwords or password option, ssh_auth:check_password/3 performs a PBKDF2-SHA256 compu
Indicators of compromise
- CVE-2026-48859cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48859