CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107708

MEDIUMCVSS 4.9NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a ma

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107708 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107708

MEDIUMCVSS 4.9NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a ma

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]