AI description
CVE-2026-59997 describes a vulnerability within the `internal-sftp` component of `sshd` in OpenSSH versions prior to 10.4. The core issue stems from the fact that `internal-sftp` only processes the first nine command-line arguments. This limitation can be significant if later command-line arguments are intended to enforce specific security properties for an SFTP connection. An unauthenticated attacker could potentially bypass these intended security measures by providing arguments beyond the ninth position, thereby altering the expected security behavior of the SFTP connection. While exploitation can occur remotely over a network without requiring privileges, successful exploitation does necessitate user interaction.
- Description
- internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- openssh
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.5
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- Severity
- MEDIUM
- cve@mitre.org
- CWE-1284
- Hype score
- Not currently trending
OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース https://t.co/Q33JNZD6fK
@yousukezan
8 Jul 2026
1625 Impressions
3 Retweets
12 Likes
4 Bookmarks
0 Replies
0 Quotes
OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #openssh #ssh https://t.co/iOrr2QHVsE
@omokazuki
8 Jul 2026
125 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have he… https://t.co/AS7keomzCl ----- Traducción: CVE-2026-59997 int… https://t.co/utmtNg
@infoflowcloud
8 Jul 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*",
"matchCriteriaId": "947E3B1E-F0DF-47BC-87D8-358B55B164AD",
"versionEndExcluding": "10.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]