CVE-2026-106589

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/10/2026
Last modified:
06/10/2026

Description

In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY devices.

References to Advisories, Solutions, and Tools