CyberRota Analysis
AI-GeneratedThe vulnerability in OpenSSH's scp command allows files to be inadvertently placed in the parent directory of the intended target when transferring between two remote locations. This misbehavior could lead to unauthorized file access or overwriting of existing files, posing a risk to data integrity and confidentiality. Organizations using affected versions of OpenSSH should prioritize patching to mitigate potential exploitation risks.
CVE
CVE-2026-59996
Severity
MEDIUM
CVSS
4.2
EPSS
0.25%
Original NVD Description
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
Related CVEs
Other vulnerabilities affecting the same vendor(s)