Command-Line Injection Vulnerability in OpenSSH by OpenBSD
CVE-2026-106583

2.5LOW

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106583?

A command-line injection vulnerability has been identified in OpenSSH versions before 10.6, where the presence of a $ or \ character in a command-line username can lead to unintended command execution. This flaw may allow attackers to manipulate the execution of commands, posing potential risks to the integrity and confidentiality of the system. It is advised to upgrade to the latest version of OpenSSH to mitigate these risks.

Affected Version(s)

OpenSSH 0 < 10.6

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.