CVE-2026-59846
published 2026-07-21CVE-2026-59846: A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables…
PriorityP414low3.9CVSS 3.1
AVLACLPRLUIRSUCLILAN
EPSS
0.11%
1.8th percentile
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| libssh | libssh | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.13.9LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
vendor_redhat3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Red Hat libssh ProxyCommand Username os command injection (Nessus ID 330077)
vuldb·2026-07-27·CVSS 3.9
CVE-2026-59846 [LOW] Red Hat libssh ProxyCommand Username os command injection (Nessus ID 330077)
A vulnerability marked as very critical has been reported in Red Hat libssh. This vulnerability affects unknown code of the component ProxyCommand. The manipulation of the argument Username leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-59846. The attack is possible to be carried out remotely. No exploit exists.
GHSA
A flaw was found in libssh.
ghsa_unreviewed·2026-07-21
CVE-2026-59846 [LOW] A flaw was found in libssh.
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
Red Hat
libssh: libssh: information disclosure via ProxyCommand %r username expansion
vendor_redhat·2026-07-21·CVSS 3.9
CVE-2026-59846 [LOW] libssh: libssh: information disclosure via ProxyCommand %r username expansion
libssh: libssh: information disclosure via ProxyCommand %r username expansion
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
Mitigation: Make sure you are not executing connections with untrusted username inputs.
Package: libssh (Red Hat Enterprise Linux 10) - Fix deferred
Package: libssh (Red Hat Enterprise Linux 8) - Fix deferred
Package: libssh (Red Hat Enterprise Linux 9) - Fix deferred
Package: libssh (Red Hat Hardened Images) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion [fedora-all]
bugzilla·2026-07-21·CVSS 3.9
CVE-2026-59846 [LOW] CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion [fedora-all]
CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw was found in libssh username handling for ProxyCommand expansion. The ssh_check_username_syntax() validation path in src/misc.c used an incomplete dangerous-character filter for usernames expanded through %r. As a result, specially crafted usernames containing shell-significant characters could reach shell-evaluated ProxyCommand handling and influence shell expansion, exposing environment variables and causing unintended shell behavior. This issue affects c
Bugzilla
CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion
bugzilla·2026-07-08·CVSS 3.9
CVE-2026-59846 [LOW] CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion
CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion
A flaw was found in libssh username handling for ProxyCommand expansion. The ssh_check_username_syntax() validation path in src/misc.c used an incomplete dangerous-character filter for usernames expanded through %r. As a result, specially crafted usernames containing shell-significant characters could reach shell-evaluated ProxyCommand handling and influence shell expansion, exposing environment variables and causing unintended shell behavior. This issue affects clients that combine untrusted username input with ProxyCommand-style shell execution.
2026-07-21
Published