PT-2026-56287 · Openssh+4 · Openssh+4

CVE-2026-59996

·

Published

2026-07-08

·

Updated

2026-08-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenSSH versions prior to 10.4
Description The scp utility may place a file in the parent directory of the intended destination when performing a copy operation between two remote destinations.
Recommendations Update to version 10.4 or later.

Exploit

Fix

DoS

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47756
ALSA-2026:47757
AZL-92039
CVE-2026-59996
ECHO-CEAA-464E-A66E
JLSEC-2026-1320
OESA-2026-3350
OESA-2026-3351
OESA-2026-3352
OESA-2026-3428
OPENSUSE-SU-2026:21477-1
SUSE-SU-2026:22978-1
SUSE-SU-2026:3605-1
USN-8533-1

Affected Products

Ibm Aix
Linuxmint
Openssh
Rocky Linux
Ubuntu