logo

OpenSSH 10.3 Patches Command Execution and “scp” Privilege Escalation

ID: ca95b2ee-0129-5fe5-b0c9-30e06118ee4b

STIX ID: report--ca95b2ee-0129-5fe5-b0c9-30e06118ee4b

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-04-03

Date Updated: 2026-04-23

Author: Ddos

...
...

OpenSSH 10.3 addresses multiple vulnerabilities including CVE-2026-35386 (improper validation of shell metacharacters in usernames that can enable client-side command execution when %u is expanded in ssh_config Match exec), CVE-2026-35385 (scp legacy mode failing to clear setuid/setgid bits when downloading as root, risking privilege escalation), CVE-2026-35414 (incorrect certificate principal matching when names contain commas), and fixes for ECDSA algorithm enforcement and multiplexing confirmation bypasses; administrators are advised to upgrade because some issues can enable command execution or privilege escalation under specific configurations, though no active exploitation is reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.