SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-59846

LOW · CVSS 3.9 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A vulnerability in libssh allows a malicious username to exploit the ProxyCommand handling by injecting shell metacharacters, which can lead to the exposure of environment variables and unintended shell behavior. While the severity is rated low, it poses a risk for systems utilizing libssh for proxy connections. Organizations that rely on libssh for secure communications should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-59846
Severity
LOW
CVSS
3.9
EPSS
0.12%

Original NVD Description

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

Related CVEs

Other vulnerabilities affecting the same vendor(s)