# CVE-2026-95651 ## Unauthenticated GSS-TSIG keytab update in Linux Node Agent fixed in build 6500 **Severity:** Critical **CVE ID:** CVE-2026-95651 **Affected Software Version(s):** DDI Central Linux Node Agent 6.3.1 / Build 6301 and below **Fixed Version:** Build 6500 **Fixed on:** September 17, 2026 **Details:** ManageEngine DDI Central Linux Node Agent 6.3.1 build 6301 and earlier contained an authentication vulnerability in the GSS-TSIG keytab update functionality. The affected Linux Node Agent endpoint responsible for updating the GSS-TSIG keytab did not enforce authentication before accepting a keytab update. An unauthenticated network client with access to the Linux Node Agent listener could therefore submit a keytab that replaced the active BIND GSS-TSIG keytab and caused the configured BIND reload operation to be executed. The vulnerability has been fixed by adding authentication checks to the affected endpoint. Keytab update requests are now authorized before the GSS-TSIG configuration can be modified or the corresponding BIND reload operation can proceed. The developer changes also specifically added token authentication and user authorization to the GSS-TSIG agent configuration endpoint. **Impact:** Successful exploitation of this vulnerability could allow an unauthenticated network attacker with access to the Linux Node Agent listener to replace the legitimate GSS-TSIG keytab used by BIND and trigger a DNS service reload. In environments using GSS-TSIG, replacing the legitimate Kerberos service key could disrupt authentication for legitimate secure dynamic DNS clients and introduce an attacker-controlled service key for subsequent Kerberos/GSS-TSIG interactions. The reported proof demonstrated modification of the security-sensitive keytab and execution of the BIND reload operation; arbitrary DNS updates were not demonstrated as part of the report. **Steps to upgrade:** Update your DDI Central installation and Linux Node Agent instances to build 6500 or later using the corresponding service pack. **Acknowledgements:** This issue was reported by sealldev.