CVE-2026-48855: SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured

Published Jun 10, 2026
·
Updated

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (sshsftpd module) allows File Discovery.

The SSHFXPREADLINK handler in sshsftpd sends the raw result of file:readlink/2 to the client without calling chrootfilename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; sshsftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSHFXPREADLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.

The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.

This vulnerability is associated with program files lib/ssh/src/sshsftpd.erl.

This issue affects OTP from OTP 17.0 before 29.0.2, 28.5.0.2 and 27.3.4.13 corresponding to ssh from 3.0.1 before 6.0.1, 5.5.2.1 and 5.2.11.8.

Other sources

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (sshsftpd module) allows File Discovery.

The SSHFXPREADLINK handler in sshsftpd sends the raw result of file:readlink/2 to the client without calling chrootfilename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; sshsftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSHFXPREADLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.

The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.

This vulnerability is associated with program files lib/ssh/src/sshsftpd.erl.

This issue affects OTP from OTP 17.0 before OTP 29.0.2, OTP 28.5.0.2 and OTP 27.3.4.13, corresponding to ssh from 3.0.1 before 6.0.1, 5.5.2.1 and 5.2.11.8.

MITRE

SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured

Microsoft

Affected Software

9 affected componentsFixes available
Erlang OTP>=17.0<29.0.2, >=17.0<28.5.0.2, >=17.0<27.3.4.13
Erlang ssh>=3.0.1<6.0.1, >=3.0.1<5.5.2.1, >=3.0.1<5.2.11.8
Erlang Erlang\/otp>=17.0<27.3.4.13
Erlang Erlang\/otp>=28.0<28.5.0.2
Erlang Erlang\/otp>=29.0<29.0.2
Erlang Erlang\/ssh>=3.0.1<5.2.11.8
Erlang Erlang\/ssh>=5.5<5.5.2.1
Erlang Erlang\/ssh>=6.0<6.0.1
Microsoft azl3 erlang 26.2.5.20-1<26.2.5.21-2
26.2.5.21-2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 26.2.5.21-2
  2. Upgrade

    Upgrade Erlang OTP ssh (ssh_sftpd module) to a version that resolves this vulnerability.

    Fixed in 29.0.2
  3. Upgrade

    Upgrade Erlang OTP ssh (ssh_sftpd module) to a version that resolves this vulnerability.

    Fixed in 28.5.0.2
  4. Upgrade

    Upgrade Erlang OTP ssh (ssh_sftpd module) to a version that resolves this vulnerability.

    Fixed in 27.3.4.13
  5. Compensating control

    If upgrading is not immediately possible, mitigate File Discovery by restricting/limiting SFTP access so that unauthorized actors cannot authenticate and issue SFTP READLINK requests (e.g., enforce strong authentication and reduce who can reach the SFTP service).

Event History

Jun 10, 2026
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 17, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:02 AM
Affected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-48855?

The severity of CVE-2026-48855 is classified as low with a CVSS score of 4.0.

2

What type of vulnerability is CVE-2026-48855?

CVE-2026-48855 is an exposure of sensitive information vulnerability that allows file discovery.

3

How does CVE-2026-48855 affect the Erlang OTP ssh module?

CVE-2026-48855 allows the SFTP READLINK handler to leak absolute backend filesystem paths when root is configured.

4

Who is affected by CVE-2026-48855?

CVE-2026-48855 affects users of the Erlang OTP ssh module, particularly in configurations where root access is allowed.

5

How can CVE-2026-48855 be mitigated?

Mitigation for CVE-2026-48855 involves updating the Erlang OTP to a version that addresses this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203