CVE-2026-106583: Low severity OpenSSH OpenSSH vulnerability
Published Oct 6, 2026
·Updated
In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.
Affected Software
1 affected component
OpenSSH OpenSSH<10.6
Event History
Oct 6, 2026
CVE Published
via MITRE·11:42 PM
Data Sourced
via MITRE·11:42 PM
DescriptionSeverityWeakness
Oct 7, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What conditions are required for exploitation?
An attacker needs local access and low privileges. Exploitation has high attack complexity and does not require user interaction.
2
Which environments should be prioritized for review?
Review systems running OpenSSH versions before 10.6, particularly where command-line usernames may contain attacker-controlled $ or \ characters.
3
What is the expected security impact?
The CVSS vector indicates low integrity impact, with no confidentiality or availability impact.