CVE-2026-106552: Medium severity OpenSSH sftp vulnerability
In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Clients using the OpenSSH sftp recursive copy functionality against an SFTP server are exposed if their OpenSSH version is before 10.6. The server can cause files to be written outside the intended destination during that operation.
What does an attacker need to exploit it?
An attacker needs to control or operate the SFTP server that the client connects to, and the client must perform a recursive copy operation. User interaction is required, and exploitation is rated high complexity.
What is the potential impact?
The issue can cause files to be written to unintended locations through directory traversal. The stated impact includes low integrity and availability impact, with no confidentiality impact.
How can this be remediated?
Upgrade OpenSSH to version 10.6 or later. The affected versions are OpenSSH releases before 10.6.