CVE-2026-59996
published 2026-07-08CVE-2026-59996: scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
PriorityP427medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
EPSS
0.25%
16.3th percentile
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | openssh | < 10.4 | 10.4 |
| openbsd | openssh | — | — |
| ubuntu | openssh | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vendor_redhat5.4MEDIUM
vendor_ubuntu5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenBSD OpenSSH up to 10.3 SCP path traversal
vuldb·2026-07-08·CVSS 4.2
CVE-2026-59996 [MEDIUM] OpenBSD OpenSSH up to 10.3 SCP path traversal
A vulnerability categorized as problematic has been discovered in OpenBSD OpenSSH up to 10.3. This impacts an unknown function of the component SCP. Such manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-59996. The attack may be performed from remote. There is no available exploit.
GHSA
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
ghsa_unreviewed·2026-07-08
CVE-2026-59996 [MEDIUM] CWE-23 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2026-07-13·CVSS 5.4
CVE-2026-60001 [MEDIUM] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH sftp did not properly constrain the location
of downloaded files when connecting to an attacker-controlled server. An
attacker could possibly use this issue to write files to unintended
locations on the file system. (CVE-2026-59995)
It was discovered that OpenSSH scp could place files in the parent
directory of the intended destination when copying between two remote
hosts. An attacker could possibly use this issue to write files to
unintended locations. (CVE-2026-59996)
It was discovered that OpenSSH internal-sftp only recognized the first nine
command-line arguments, This could result in certain security-sensitive
arguments being ignored, contrary to expectations. (CV
Red Hat
openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy
vendor_redhat·2026-07-08·CVSS 5.4
CVE-2026-59996 [MEDIUM] CWE-22 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy
openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
A flaw was found in OpenSSH, a widely used tool for secure remote access. When a user attempts to copy files between two different remote systems using the `scp` command, the file might be incorrectly placed in a directory above the intended destination. This unintended file placement could lead to data integrity issues or, in some cases, unauthorized access to sensitive information if files are stored in an exposed location.
Statement: Conditions for Exploitation: Exploitation requires specific user actions and conditions, as the vulnerability only triggers when a use
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59996 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy [fedora-all]
bugzilla·2026-07-08·CVSS 4.2
CVE-2026-59996 [MEDIUM] CVE-2026-59996 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy [fedora-all]
CVE-2026-59996 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
Bugzilla
CVE-2026-59996 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy
bugzilla·2026-07-08·CVSS 5.4
CVE-2026-59996 [MEDIUM] CVE-2026-59996 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy
CVE-2026-59996 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
2026-07-08
Published