SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59995

MEDIUM · CVSS 4.2 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

OpenSSH versions prior to 10.4 have a vulnerability in the SFTP component that allows an attacker to manipulate the file download location when using the command "sftp server:/path .". This could lead to unauthorized file access or overwriting of files on the client system, posing a risk to users who rely on SFTP for secure file transfers. Organizations utilizing OpenSSH for SFTP should prioritize updating to version 10.4 or later to mitigate this risk.

CVE
CVE-2026-59995
Severity
MEDIUM
CVSS
4.2
EPSS
0.25%

Original NVD Description

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)