CVE-2026-0964
6.3 MEDIUMA malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory
Published: 2026-03-26 · Last updated: 2026-05-19
Severity and scoring
- CVSS
- 6.3 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- CWE
- CWE-22
Affected products
| Vendor | Product |
|---|---|
| libssh | enterprise_linux, hardened_images, libssh |
| redhat | enterprise_linux, hardened_images, libssh |
Description
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-0964
- [Other]https://access.redhat.com/errata/RHSA-2026:18160
- [Other]https://access.redhat.com/errata/RHSA-2026:18683
- [Vendor advisory]https://access.redhat.com/security/cve/CVE-2026-0964
- [Vendor advisory]https://bugzilla.redhat.com/show_bug.cgi?id=2436979
- [Other]https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/
Related CVEs
Same vendor
- CVE-2026-1767 — A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component (5.6 MEDIUM)
- CVE-2026-1766 — A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 com... (5.6 MEDIUM)
- CVE-2026-11793 — A stack buffer overflow flaw was found in 389 Directory Server (4.9 MEDIUM)
- CVE-2026-11790 — A flaw was found in 389 Directory Server (4.9 MEDIUM)
- CVE-2026-11789 — A flaw was found in 389 Directory Server (4.9 MEDIUM)
Same CWE
- CVE-2026-48777 — FileBrowser Quantum is a free, self-hosted, web-based file manager
- CVE-2026-8442 — The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8 (8.1 HIGH)
- CVE-2026-49766 — Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions (9.9 CRITICAL)
- CVE-2026-49061 — Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions (7.5 HIGH)
- CVE-2026-40779 — Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions (7.7 HIGH)