CVE-2026-106587: Low severity OpenSSH sshd vulnerability
Published Oct 6, 2026
·Updated
In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled.
Affected Software
1 affected component
OpenSSH sshd<10.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenSSHto a version that resolves this vulnerability.Fixed in 10.6
Event History
Oct 6, 2026
CVE Published
via MITRE·09:01 PM
Data Sourced
via MITRE·09:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires local access, low privileges, and high attack complexity. No user interaction is required.
2
What security impact is indicated?
The reported impact is limited to integrity and availability; no confidentiality impact is indicated. The severity is low, with a score of 3.6.
3
Which deployments need to be reviewed?
Review sshd configurations on OpenSSH versions before 10.6, particularly configuration options set to the value "none" where that value is intended to disable a feature.