AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-59997

MEDIUM · CVSS 4.2 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

OpenSSH versions prior to 10.4 have a vulnerability in the internal SFTP implementation, where only the first nine command-line arguments are recognized, potentially compromising the security properties of SFTP connections. This limitation may allow for unintended configurations that could be exploited by attackers. Organizations using affected versions of OpenSSH should prioritize patching to mitigate potential security risks associated with this flaw.

CVE
CVE-2026-59997
Severity
MEDIUM
CVSS
4.2
EPSS
0.18%

Original NVD Description

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

Related CVEs

Other vulnerabilities affecting the same vendor(s)