Description

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.

INFO

Published Date :

2026-03-26T20:06:28.871Z

Last Modified :

2026-05-04T13:07:29.979Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-0964 vulnerability.

Vendors Products
Libssh
  • Libssh
Redhat
  • Enterprise Linux
  • Hardened Images
  • Hummingbird
  • Openshift
  • Openshift Container Platform

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact