CVE-2026-59996: Medium severity OpenSSH OpenSSH vulnerability
Last updated 13 July 2026
Other sources
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.8p1-9 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.4p1-1 - Upgrade
Upgrade
OpenSSHto a version that resolves this vulnerability.Fixed in 10.4 - Compensating control
Ensure scp copies are not performed between two remote destinations on affected OpenSSH versions (<10.4) to prevent the parent-directory write condition.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59996?
CVE-2026-59996 has a medium severity rating of 4.2.
How do I fix CVE-2026-59996?
To fix CVE-2026-59996, upgrade OpenSSH to version 10.4 or later.
What does CVE-2026-59996 affect?
CVE-2026-59996 affects the scp command in OpenSSH versions prior to 10.4.
What is the risk associated with CVE-2026-59996?
The risk associated with CVE-2026-59996 is classified as medium, rated at 28.
Could CVE-2026-59996 lead to unauthorized file access?
Yes, CVE-2026-59996 could potentially lead to unauthorized file access by placing files in unexpected parent directories.