Improper Neutralization of Argument Delimiters in a Command in OpenSSH - CVE-2026-59997

 

Improper Neutralization of Argument Delimiters in a Command in OpenSSH - CVE-2026-59997

Published: July 15, 2026


Vulnerability identifier: #VU137700
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59997
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass security-relevant SFTP server options.

The vulnerability exists due to improper input handling in the internal-sftp SFTP server implementation when processing long command lines. A remote privileged user can supply a command line with security-relevant options placed after the ninth argument to bypass security-relevant SFTP server options.

Only configurations using the internal-sftp SFTP server implementation are affected.


Affected software

OpenSSH
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
pam_ssh_agent_auth
openssh-ldap
openssh-help
openssh
openssh-askpass
openssh-cavs
openssh-clients
openssh-debuginfo
openssh-debugsource
openssh-keycat
openssh-server
openssh (Ubuntu package)
openssh-sk-dummy
openssh-doc
openssh-server-config-disallow-rootlogin
openssh-cavs-debuginfo
openssh-askpass-gnome-debugsource
openssh-askpass-gnome
openssh-askpass-gnome-debuginfo
openssh-server-debuginfo
openssh-common-debuginfo
openssh-helpers
openssh-clients-debuginfo
openssh-fips
openssh-common
openssh-helpers-debuginfo

How to mitigate CVE-2026-59997

Install security update from vendor's website.

OpenSSH - update to 10.4p1
pam_ssh_agent_auth - addressed in versions 0.10.3-9.39, 0.10.4-4.46, 0.10.4-5.17, 0.10.4-5.22
openssh-ldap - update to 8.2p1-39
openssh-help - addressed in versions 8.2p1-39, 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh - addressed in versions 8.2p1-39, 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-askpass - addressed in versions 8.2p1-39, 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-cavs - update to 8.2p1-39
openssh-clients - addressed in versions 8.2p1-39, 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-debuginfo - addressed in versions 8.2p1-39, 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-debugsource - addressed in versions 8.2p1-39, 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-keycat - addressed in versions 8.2p1-39, 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh-server - addressed in versions 8.2p1-39, 8.8p1-46, 9.6p1-17, 9.6p1-22
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.16, 1:9.6p1-3ubuntu13.18, 1:10.2p1-2ubuntu3.4
openssh - update to 9.6p1-14
openssh-askpass - update to 9.6p1-14
openssh-clients - update to 9.6p1-14
openssh-keycat - update to 9.6p1-14
openssh-server - update to 9.6p1-14
openssh-sk-dummy - update to 9.6p1-14
openssh-doc - update to 9.6p1-14
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.49.1
openssh-cavs-debuginfo - update to 9.6p1-150600.6.49.1
openssh-cavs - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.49.1
openssh - update to 9.6p1-150600.6.49.1
openssh-server-debuginfo - update to 9.6p1-150600.6.49.1
openssh-common-debuginfo - update to 9.6p1-150600.6.49.1
openssh-debugsource - update to 9.6p1-150600.6.49.1
openssh-clients - update to 9.6p1-150600.6.49.1
openssh-helpers - update to 9.6p1-150600.6.49.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.49.1
openssh-fips - update to 9.6p1-150600.6.49.1
openssh-common - update to 9.6p1-150600.6.49.1
openssh-debuginfo - update to 9.6p1-150600.6.49.1
openssh-server - update to 9.6p1-150600.6.49.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.49.1

External References

Related Security Bulletins