CVE-2026-35414 is a medium impact CVE which is OpenSSH vulnerability related to improper handling of the authorized_keys principals option in specific configurations involving Certificate Authorities. Under certain uncommon conditions, this could lead to misinterpretation of input.
VCF Operation for Networks 6.14.0
VCF Operation for Networks 6.14.1
VCF Operation for Networks 6.14.2
CVE-2026-35414 is fixed in future release of VCF Operation for Networks version 6.14.3
Should you require further information please contact Broadcom Support: Creating and managing Broadcom support cases
CVE-2026-35414 is fixed in 1:8.9p1-3ubuntu0.15 Openssh version.
To query Openssh version in VCF Operation for Networks appliance, please take a SSH session and run command : dpkg -l | grep openssh
Below attached is a sample output: