AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-59996

MEDIUM · CVSS 4.2 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability in OpenSSH's scp command allows files to be inadvertently placed in the parent directory of the intended target when transferring between two remote locations. This misbehavior could lead to unauthorized file access or overwriting of existing files, posing a risk to data integrity and confidentiality. Organizations using affected versions of OpenSSH should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-59996
Severity
MEDIUM
CVSS
4.2
EPSS
0.25%

Original NVD Description

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

Related CVEs

Other vulnerabilities affecting the same vendor(s)