OS Command Injection in libssh - CVE-2026-59846

 

OS Command Injection in libssh - CVE-2026-59846

Published: July 27, 2026


Vulnerability identifier: #VU139529
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59846
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper neutralization of special elements in the ProxyCommand username expansion in the client component when expanding a user-supplied username into a ProxyCommand executed by the shell. A local user can supply a malicious username and trick the victim into initiating a connection to disclose sensitive information.

User interaction is required to initiate the connection, and the issue is limited to the client side.


Affected software

libssh
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Basesystem Module
openSUSE Leap
Ubuntu
libssh (Ubuntu package)
libssh4-64bit
libssh4-64bit-debuginfo
libssh4-32bit
libssh4-32bit-debuginfo
libssh4
libssh4-debuginfo
libssh-debugsource
libssh-devel
libssh-config
libssh (Red Hat package)

How to mitigate CVE-2026-59846

Install security update from vendor's website.

libssh - addressed in versions 0.11.5, 0.12.1
libssh (Ubuntu package) - addressed in versions 0.9.6-2ubuntu0.22.04.8, 0.10.6-2ubuntu0.5, 0.11.3-1ubuntu2.1
libssh4-64bit - addressed in versions 0.9.8-150400.3.20.1, 0.9.8-150600.11.15.1
libssh4-64bit-debuginfo - addressed in versions 0.9.8-150400.3.20.1, 0.9.8-150600.11.15.1
libssh4-32bit - addressed in versions 0.9.8-150400.3.20.1, 0.9.8-150600.11.15.1
libssh4-32bit-debuginfo - addressed in versions 0.9.8-150400.3.20.1, 0.9.8-150600.11.15.1
libssh4 - addressed in versions 0.9.8-150400.3.20.1, 0.9.8-150600.11.15.1
libssh4-debuginfo - addressed in versions 0.9.8-150400.3.20.1, 0.9.8-150600.11.15.1
libssh-debugsource - addressed in versions 0.9.8-150400.3.20.1, 0.9.8-150600.11.15.1
libssh-devel - addressed in versions 0.9.8-150400.3.20.1, 0.9.8-150600.11.15.1
libssh-config - addressed in versions 0.9.8-150400.3.20.1, 0.9.8-150600.11.15.1
libssh (Red Hat package) - addressed in versions 0.10.4-19.el9_8, 0.12.0-3.el10_2

External References

Related Security Bulletins