CVE-2026-106583

CVE & Vulnerabilities · October 9, 2026

CVE & Vulnerabilities·nvd.nist.gov

A newly tracked flaw, CVE-2026-106583, affects the ssh client in OpenSSH versions before 10.6: a username containing a dollar sign or backslash passed on the command line can be interpreted in unintended ways, opening the door to injection. Because usernames are often supplied by scripts, automation, or remote configuration rather than typed by hand, the bug could let an attacker smuggle shell metacharacters into an SSH invocation. Admins and tool maintainers should update to OpenSSH 10.6 or later and sanitize any usernames assembled programmatically before they reach the ssh command line.

// source: nvd.nist.gov ↗

← Back to Blog