Path traversal in OpenSSH - CVE-2026-59996
Published: July 15, 2026
Vulnerability identifier: #VU137699
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59996
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to write files outside the intended target directory.
The vulnerability exists due to improper path restriction in scp(1) when copying files between two remote destinations. A remote attacker can operate a malicious server to write files outside the intended target directory.
Affected software
OpenSSH
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
pam_ssh_agent_auth
openssh-help
openssh
openssh-askpass
openssh-clients
openssh-debuginfo
openssh-debugsource
openssh-keycat
openssh-server
openssh (Ubuntu package)
openssh-sk-dummy
openssh-doc
openssh-server-config-disallow-rootlogin
openssh-cavs-debuginfo
openssh-cavs
openssh-askpass-gnome-debugsource
openssh-askpass-gnome
openssh-askpass-gnome-debuginfo
openssh-server-debuginfo
openssh-helpers-debuginfo
openssh-common
openssh-fips
openssh-clients-debuginfo
openssh-helpers
openssh-common-debuginfo
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
pam_ssh_agent_auth
openssh-help
openssh
openssh-askpass
openssh-clients
openssh-debuginfo
openssh-debugsource
openssh-keycat
openssh-server
openssh (Ubuntu package)
openssh-sk-dummy
openssh-doc
openssh-server-config-disallow-rootlogin
openssh-cavs-debuginfo
openssh-cavs
openssh-askpass-gnome-debugsource
openssh-askpass-gnome
openssh-askpass-gnome-debuginfo
openssh-server-debuginfo
openssh-helpers-debuginfo
openssh-common
openssh-fips
openssh-clients-debuginfo
openssh-helpers
openssh-common-debuginfo
How to mitigate CVE-2026-59996
Install security update from vendor's website.
OpenSSH - update to 10.4p1
pam_ssh_agent_auth - addressed in versions 0.10.4-4.46, 0.10.4-5.17, 0.10.4-5.22
openssh-help - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-askpass - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-clients - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-debuginfo - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-debugsource - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-keycat - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-server - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.16, 1:9.6p1-3ubuntu13.18, 1:10.2p1-2ubuntu3.4
openssh-sk-dummy - update to 9.6p1-11
openssh-server - update to 9.6p1-11
openssh-keycat - update to 9.6p1-11
openssh-clients - update to 9.6p1-11
openssh-askpass - update to 9.6p1-11
openssh-doc - update to 9.6p1-11
openssh - update to 9.6p1-11
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.49.1
openssh-cavs-debuginfo - update to 9.6p1-150600.6.49.1
openssh-cavs - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.49.1
openssh - update to 9.6p1-150600.6.49.1
openssh-server-debuginfo - update to 9.6p1-150600.6.49.1
openssh-server - update to 9.6p1-150600.6.49.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.49.1
openssh-debugsource - update to 9.6p1-150600.6.49.1
openssh-debuginfo - update to 9.6p1-150600.6.49.1
openssh-common - update to 9.6p1-150600.6.49.1
openssh-fips - update to 9.6p1-150600.6.49.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.49.1
openssh-helpers - update to 9.6p1-150600.6.49.1
openssh-clients - update to 9.6p1-150600.6.49.1
openssh-common-debuginfo - update to 9.6p1-150600.6.49.1
openssh - addressed in versions 10.0p1-11.fc43, 10.2p1-13.fc44
pam_ssh_agent_auth - addressed in versions 0.10.4-4.46, 0.10.4-5.17, 0.10.4-5.22
openssh-help - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-askpass - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-clients - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-debuginfo - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-debugsource - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-keycat - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-server - addressed in versions 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.16, 1:9.6p1-3ubuntu13.18, 1:10.2p1-2ubuntu3.4
openssh-sk-dummy - update to 9.6p1-11
openssh-server - update to 9.6p1-11
openssh-keycat - update to 9.6p1-11
openssh-clients - update to 9.6p1-11
openssh-askpass - update to 9.6p1-11
openssh-doc - update to 9.6p1-11
openssh - update to 9.6p1-11
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.49.1
openssh-cavs-debuginfo - update to 9.6p1-150600.6.49.1
openssh-cavs - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.49.1
openssh - update to 9.6p1-150600.6.49.1
openssh-server-debuginfo - update to 9.6p1-150600.6.49.1
openssh-server - update to 9.6p1-150600.6.49.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.49.1
openssh-debugsource - update to 9.6p1-150600.6.49.1
openssh-debuginfo - update to 9.6p1-150600.6.49.1
openssh-common - update to 9.6p1-150600.6.49.1
openssh-fips - update to 9.6p1-150600.6.49.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.49.1
openssh-helpers - update to 9.6p1-150600.6.49.1
openssh-clients - update to 9.6p1-150600.6.49.1
openssh-common-debuginfo - update to 9.6p1-150600.6.49.1
openssh - addressed in versions 10.0p1-11.fc43, 10.2p1-13.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSH
- Ubuntu update for openssh
- Fedora 43 update for openssh
- Fedora 44 update for openssh
- Anolis OS update for openssh
- SUSE update for openssh
- openEuler 24.03 LTS SP3 update for openssh
- openEuler 24.03 LTS SP1 update for openssh
- openEuler 22.03 LTS SP4 update for openssh
- openEuler 24.03 LTS SP4 update for openssh