CVE-2026-59997
published 2026-07-08CVE-2026-59997: internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would…
PriorityP426medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.18%
7.0th percentile
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | openssh | < 10.4 | 10.4 |
| openbsd | openssh | — | — |
| ubuntu | openssh | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
vendor_ubuntu5.4MEDIUM
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2026-07-13·CVSS 5.4
CVE-2026-60001 [MEDIUM] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH sftp did not properly constrain the location
of downloaded files when connecting to an attacker-controlled server. An
attacker could possibly use this issue to write files to unintended
locations on the file system. (CVE-2026-59995)
It was discovered that OpenSSH scp could place files in the parent
directory of the intended destination when copying between two remote
hosts. An attacker could possibly use this issue to write files to
unintended locations. (CVE-2026-59996)
It was discovered that OpenSSH internal-sftp only recognized the first nine
command-line arguments, This could result in certain security-sensitive
arguments being ignored, contrary to expectations. (CV
Red Hat
openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw
vendor_redhat·2026-07-08·CVSS 4.2
CVE-2026-59997 [MEDIUM] CWE-88 openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw
openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw
A flaw was found in OpenSSH. The internal-sftp component within sshd incorrectly processes command-line arguments, recognizing only the first nine. This limitation can prevent the application of intended security configurations for SFTP (SSH File Transfer Protocol) connections, potentially leading to a bypass of security properties.
Package: openssh (Red Hat Enterprise Linux 10) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 6) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 7) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 8) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 9) - Fix deferred
Package: openssh (Red Hat Hardened Images) - Affected
Package: rhcos (
VulDB
OpenBSD OpenSSH up to 10.3 Internal-SFTP privilege escalation
vuldb·2026-07-08·CVSS 4.2
CVE-2026-59997 [MEDIUM] OpenBSD OpenSSH up to 10.3 Internal-SFTP privilege escalation
A vulnerability, which was classified as problematic, was found in OpenBSD OpenSSH up to 10.3. The affected element is an unknown function of the component Internal-SFTP. Executing a manipulation can lead to privilege escalation.
This vulnerability is handled as CVE-2026-59997. The attack can only be done within the local network. There is not any exploit available.
GHSA
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended securi
ghsa_unreviewed·2026-07-08
CVE-2026-59997 [MEDIUM] CWE-1284 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended securi
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
No detection rules found.
No public exploits indexed.
2026-07-08
Published