CVE-2026-0964
Last modified
CVE-2026-0964 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libssh | Libssh | < 0.11.4 |
| Redhat | Hardened Images | All versions |
| Redhat | Openshift Container Platform | 4.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux | 10.0 |
References
- https://access.redhat.com/security/cve/CVE-2026-0964Mitigation, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2436979Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-0964?
How severe is CVE-2026-0964?
How do I fix CVE-2026-0964?
Are you affected by CVE-2026-0964?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
