Input validation error in OpenSSH - CVE-2026-35386

 

Input validation error in OpenSSH - CVE-2026-35386

Published: April 29, 2026


Vulnerability identifier: #VU128473
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35386
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary shell commands.

The vulnerability exists due to improper input validation in ssh(1) when expanding %-tokens from ssh_config using a user name supplied on the command-line. A local user can supply a specially crafted user name to execute arbitrary shell commands.

Exploitation requires a configuration that uses the %u token in a Match exec block.


Affected software

OpenSSH
IBM i
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Ubuntu
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pam_ssh_agent_auth
openssh (Red Hat package)
openssh-server
openssh-ldap
openssh-keycat
openssh-clients
openssh-cavs
openssh-askpass
openssh
openssh (Ubuntu package)
openssh-help
openssh-debugsource
openssh-debuginfo

How to mitigate CVE-2026-35386

Install security update from vendor's website.

OpenSSH - update to 10.3p1
pam_ssh_agent_auth - update to 0.10.3-7.29.0.1
pam_ssh_agent_auth - update to 0.10.4-5.13
openssh (Red Hat package) - addressed in versions 8.0p1-7.el8_4.2, 8.0p1-15.el8_6.5, 8.0p1-20.el8_8.4, 8.0p1-29.el8_10, 8.7p1-30.el9_2.11, 8.7p1-45.el9_6.3, 8.7p1-49.el9_7, 9.9p1-7.el10_0.3, 9.9p1-14.el10_1
openssh-server - update to 8.0p1-29.0.1
openssh-ldap - update to 8.0p1-29.0.1
openssh-keycat - update to 8.0p1-29.0.1
openssh-clients - update to 8.0p1-29.0.1
openssh-cavs - update to 8.0p1-29.0.1
openssh-askpass - update to 8.0p1-29.0.1
openssh - update to 8.0p1-29.0.1
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.15, 1:9.6p1-3ubuntu13.16, 1:10.0p1-5ubuntu5.4, 1:10.2p1-2ubuntu3.2
openssh-help - update to 9.6p1-13
openssh-server - update to 9.6p1-13
openssh-keycat - update to 9.6p1-13
openssh-debugsource - update to 9.6p1-13
openssh-debuginfo - update to 9.6p1-13
openssh-clients - update to 9.6p1-13
openssh-askpass - update to 9.6p1-13
openssh - update to 9.6p1-13
openssh - addressed in versions 10.0p1-9.fc43, 10.2p1-8.fc44

External References

Related Security Bulletins