CVE-2026-59999
published 2026-07-08CVE-2026-59999: In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.16%
5.4th percentile
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | openssh | < 10.4 | 10.4 |
| openbsd | openssh | — | — |
| ubuntu | openssh | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat5.9MEDIUM
vendor_ubuntu5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2026-07-13·CVSS 5.4
CVE-2026-60001 [MEDIUM] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH sftp did not properly constrain the location
of downloaded files when connecting to an attacker-controlled server. An
attacker could possibly use this issue to write files to unintended
locations on the file system. (CVE-2026-59995)
It was discovered that OpenSSH scp could place files in the parent
directory of the intended destination when copying between two remote
hosts. An attacker could possibly use this issue to write files to
unintended locations. (CVE-2026-59996)
It was discovered that OpenSSH internal-sftp only recognized the first nine
command-line arguments, This could result in certain security-sensitive
arguments being ignored, contrary to expectations. (CV
Red Hat
openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
vendor_redhat·2026-07-08·CVSS 5.9
CVE-2026-59999 [MEDIUM] CWE-358 openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
A flaw was found in `sshd`, the OpenSSH server daemon. When `DisableForwarding=yes` is configured to prevent network traffic forwarding, it incorrectly fails to take precedence over `PermitTunnel=yes`. This allows a remote attacker to bypass intended security restrictions and establish a tunnel, potentially leading to unauthorized network access or circumvention of security policies, even when forwarding is explicitly disabled.
Package: openssh (Red Hat Enterprise Linux 10) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 6) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 7) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 8) - Fix deferred
Package: openssh
GHSA
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
ghsa_unreviewed·2026-07-08
CVE-2026-59999 [MEDIUM] CWE-348 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
VulDB
OpenBSD OpenSSH up to 10.3 privilege escalation
vuldb·2026-07-08·CVSS 5.9
CVE-2026-59999 [MEDIUM] OpenBSD OpenSSH up to 10.3 privilege escalation
A vulnerability was found in OpenBSD OpenSSH up to 10.3 and classified as problematic. This affects an unknown function. The manipulation results in privilege escalation.
This vulnerability was named CVE-2026-59999. The attack needs to be approached within the local network. There is no available exploit.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59999 openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options [fedora-all]
bugzilla·2026-08-11·CVSS 7.5
CVE-2026-59999 [HIGH] CVE-2026-59999 openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options [fedora-all]
CVE-2026-59999 openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
Bugzilla
CVE-2026-59999 openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
bugzilla·2026-07-08·CVSS 5.9
CVE-2026-59999 [MEDIUM] CVE-2026-59999 openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
CVE-2026-59999 openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
2026-07-08
Published