Command-Line Injection Vulnerability in OpenSSH by OpenBSD
CVE-2026-106583
2.5LOW
What is CVE-2026-106583?
A command-line injection vulnerability has been identified in OpenSSH versions before 10.6, where the presence of a $ or \ character in a command-line username can lead to unintended command execution. This flaw may allow attackers to manipulate the execution of commands, posing potential risks to the integrity and confidentiality of the system. It is advised to upgrade to the latest version of OpenSSH to mitigate these risks.
Affected Version(s)
OpenSSH 0 < 10.6