CVE-2026-59996
CVE-2026-59996 is a medium-severity vulnerability in Openbsd Openssh with a CVSS 3.x base score of 4.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-23.
Key facts
- Severity: Medium (CVSS 3.x base score 4.2)
- EPSS exploit prediction: 0% (17th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-23
- Affected product: Openbsd Openssh
- Published:
- Last modified:
Description
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
Frequently asked questions
- What is CVE-2026-59996?
- scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
- How severe is CVE-2026-59996?
- CVE-2026-59996 has a CVSS 3.x base score of 4.2, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity low, and availability low.
- Is CVE-2026-59996 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (17th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-59996?
- CVE-2026-59996 affects Openbsd Openssh. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-59996?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-59996 published?
- CVE-2026-59996 was published on 2026-07-08 and last updated on 2026-07-09.
References
- https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2
- https://www.openssh.org/releasenotes.html#10.4p1
- https://www.openwall.com/lists/oss-security/2026/07/06/5
Affected products (1)
- cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
More vulnerabilities in Openbsd Openssh
- CVE-2003-0786 — Critical (CVSS 10.0): The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled,…
- CVE-2003-0693 — Critical (CVSS 10.0): A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to…
- CVE-2002-0640 — Critical (CVSS 10.0): Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large…
- CVE-2001-0144 — Critical (CVSS 10.0): CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH…
- CVE-2000-0999 — Critical (CVSS 10.0): Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers…
- CVE-2000-0525 — Critical (CVSS 10.0): OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute…
All CVEs affecting Openbsd Openssh →
Other CWE-23 vulnerabilities
- CVE-2026-52813 — Critical (CVSS 10.0): Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences…
- CVE-2026-8326 — Critical (CVSS 10.0): Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing…
- CVE-2026-33494 — Critical (CVSS 10.0): ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based…
- CVE-2023-3941 — Critical (CVSS 10.0): Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system…
- CVE-2024-24578 — Critical (CVSS 10.0): RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior…
- CVE-2012-6069 — Critical (CVSS 10.0): The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an…
Browse all CWE-23 vulnerabilities →
Threat intelligence
Threat-intel indicators referencing this CVE:
- 118.193.56.184 (ipv4-addr)
- 101.36.114.124 (ipv4-addr)
- 152.32.149.19 (ipv4-addr)
- 165.22.134.80 (ipv4-addr)
- 172.174.212.111 (ipv4-addr)
- 43.157.27.211 (ipv4-addr)
- 112.124.67.212 (ipv4-addr)
- 121.43.116.1 (ipv4-addr)