cbcvebase.
CVE-2026-0964
published 2026-03-26

CVE-2026-0964: A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be…

PriorityP336medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
0.41%
33.1th percentile
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlibssh< libssh 0.12.0-1 (forky)libssh 0.12.0-1 (forky)
libsshlibssh< 0.11.40.11.4
libsshlibssh>= 0 < 0.12.0-10.12.0-1
libsshlibssh>= 0 < 0.9.6-2ubuntu0.22.04.60.9.6-2ubuntu0.22.04.6
libsshlibssh>= 0 < 0.10.6-2ubuntu0.30.10.6-2ubuntu0.3
libsshlibssh>= 0 < 0.11.2-1ubuntu0.20.11.2-1ubuntu0.2
libsshlibssh>= 0 < 0.6.3-4.3ubuntu0.6+esm40.6.3-4.3ubuntu0.6+esm4
libsshlibssh>= 0 < 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm60.8.0~20170825.94fa1e38-1ubuntu0.7+esm6
libsshlibssh>= 0 < 0.9.3-2ubuntu2.5+esm30.9.3-2ubuntu2.5+esm3
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatopenshift_container_platform

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv3.05.0MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.