Configuration Parsing Issue in OpenSSH Affecting Secure Shell Services
CVE-2026-106587

3.6LOW

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106587?

A configuration parsing issue exists in OpenSSH prior to version 10.6, where the value 'none' for a specific configuration option can be mistakenly interpreted as a filename. This misinterpretation can inadvertently enable certain features instead of disabling them as intended, potentially leading to unintended access. Users are encouraged to review their configurations and upgrade to mitigate associated risks.

Affected Version(s)

OpenSSH 0 < 10.6

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.