AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-59999

MEDIUM · CVSS 5.9 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A vulnerability in OpenSSH prior to version 10.4 allows the configuration option DisableForwarding=yes to be overridden by PermitTunnel=yes, potentially exposing sensitive data through unintended tunneling. This could lead to unauthorized access or data exfiltration in environments relying on these settings for secure SSH configurations. Organizations using affected versions should prioritize updates to mitigate the risk associated with this misconfiguration.

CVE
CVE-2026-59999
Severity
MEDIUM
CVSS
5.9
EPSS
0.16%

Original NVD Description

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

Related CVEs

Other vulnerabilities affecting the same vendor(s)