Privilege Escalation Vulnerability in OpenSSH by OpenBSD
CVE-2026-106589
2.9LOW
What is CVE-2026-106589?
In OpenSSH version 10.6, a vulnerability exists in specific environments like QNX 6 and SCO OpenServer 5, where sshd-session can unintentionally obtain root privileges. This issue is tied to the configurations of GatewayPorts and StreamLocalForwarding, compounded by limitations in file-descriptor passing and the unprivileged allocation of PTY devices. Users are advised to review their configuration settings to mitigate potential exploitation.
Affected Version(s)
OpenSSH 0 <= 10.6