ThreatCluster

27-Year-Old OpenBSD Vulnerability Exposed: Remote Auth Bypass Disclosed

First seen 17 Jun 2026, 17:10 UTC RedditGbhackersCybersecuritynews 80% similarity 73

Article Content

Browse articles
ThreatCluster

A vulnerability in OpenBSD's networking stack has been disclosed, allowing attackers to bypass PAP authentication due to a logic flaw in the sppp_pap_input() function. This flaw, present since the import from FreeBSD in July 1999, enables attackers to intercept and read PPPoE traffic without credentials. The vulnerability affects systems relying on the Password Authentication Protocol (PAP) during the authentication phase. OpenBSD has released a patch to address this issue. The vulnerability has persisted through nearly three decades of system updates. Argus-Systems discovered the flaw, which is now classified as a critical security risk. Users of OpenBSD are urged to apply the patch immediately to mitigate potential exploitation.

Key Points: • A critical vulnerability in OpenBSD's PAP authentication has existed for 27 years. • Attackers can bypass authentication and intercept PPPoE traffic without credentials. • OpenBSD has released a patch to address the vulnerability, urging immediate application.

ThreatCluster AI How this analysis works

Timeline

1999-07-01
OpenBSD imports PPP stack from FreeBSD
The logic flaw in the sppp_pap_input() function was introduced during this import, leading to a long-standing vulnerability.
Reddit
2026-06-16
Vulnerability disclosed
Argus-Systems revealed a remote authentication bypass in OpenBSD's kernel PPP stack, allowing credential-free access.
Reddit
2026-06-17
Patch released by OpenBSD
OpenBSD released a patch to fix the vulnerability, urging users to apply it immediately to prevent exploitation.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story