Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.openssh.org/releasenotes.html#10.6 |
|
Tue, 06 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY devices. | |
| First Time appeared |
Openbsd
Openbsd openssh |
|
| Weaknesses | CWE-272 | |
| CPEs | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openbsd
Openbsd openssh |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-06T21:21:35.996Z
Reserved: 2026-10-06T21:21:35.635Z
Link: CVE-2026-106589
No data.
Status : Received
Published: 2026-10-06T22:17:06.920
Modified: 2026-10-06T22:17:06.920
Link: CVE-2026-106589
No data.
OpenCVE Enrichment
No data.