Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59996

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 4.6
EPSS Низкий

Описание

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

A flaw was found in OpenSSH, a widely used tool for secure remote access. When a user attempts to copy files between two different remote systems using the scp command, the file might be incorrectly placed in a directory above the intended destination. This unintended file placement could lead to data integrity issues or, in some cases, unauthorized access to sensitive information if files are stored in an exposed location.

Отчет

Conditions for Exploitation: Exploitation requires specific user actions and conditions, as the vulnerability only triggers when a user explicitly initiates a file copy between two remote destinations using the scp command. Impact Limitations: The boundaries of the potential impact are highly contained. The flaw only results in unintended file placement within the parent directory of the target destination. It does not inherently lead to arbitrary code execution, denial of service, or privilege escalation, and any potential data exposure relies heavily on the existing permissions of the parent directory.

Меры по смягчению последствий

To mitigate this issue, users should avoid performing scp operations directly between two remote destinations. Instead, consider copying files from the first remote host to a local machine, and then from the local machine to the second remote host. Alternatively, use sftp or rsync for remote file transfers, as these utilities are not affected by this specific vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opensshAffected
Red Hat Enterprise Linux 7opensshAffected
Red Hat Enterprise Linux 8opensshAffected
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10opensshFixedRHSA-2026:4775730.07.2026
Red Hat Enterprise Linux 9opensshFixedRHSA-2026:4775629.07.2026
Red Hat Enterprise Linux 9opensshFixedRHSA-2026:4775629.07.2026
Red Hat Hardened Imagesopenssh-main-10.4p1-1.hum1FixedRHSA-2026:3738209.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2497944openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy

EPSS

Процентиль: 17%
0.0025
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
25 дней назад

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

CVSS3: 4.2
nvd
25 дней назад

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

CVSS3: 4.2
msrc
20 дней назад

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

CVSS3: 4.2
debian
25 дней назад

scp in OpenSSH before 10.4 may place a file in the parent directory of ...

CVSS3: 4.2
github
25 дней назад

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

EPSS

Процентиль: 17%
0.0025
Низкий

4.6 Medium

CVSS3