Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35386

Опубликовано: 02 апр. 2026
Источник: redhat
CVSS3: 3.6
EPSS Низкий

Описание

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

A flaw was found in OpenSSH. This vulnerability allows a remote attacker to achieve arbitrary command execution by injecting shell metacharacters into a username provided on the command line. Exploitation requires an untrusted username and a non-default configuration of the '%' character in ssh_config.

Отчет

Red Hat products do not ship in a configuration which is subject to this vulnerability. Additionally, the impact of the command execution is limited to the scope of the specific user account which users would need to create themselves.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10opensshFixedRHSA-2026:1338004.05.2026
Red Hat Enterprise Linux 10opensshFixedRHSA-2026:1906919.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportopensshFixedRHSA-2026:1238930.04.2026
Red Hat Enterprise Linux 8opensshFixedRHSA-2026:1338304.05.2026
Red Hat Enterprise Linux 8opensshFixedRHSA-2026:1338304.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportopensshFixedRHSA-2026:2232901.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnopensshFixedRHSA-2026:2232901.06.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2454506OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username

EPSS

Процентиль: 16%
0.00247
Низкий

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 3.6
ubuntu
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
nvd
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
msrc
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
debian
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metachar ...

CVSS3: 3.6
github
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

EPSS

Процентиль: 16%
0.00247
Низкий

3.6 Low

CVSS3