https://seclists.org/oss-sec/2026/q2/23: Announce: OpenSSH 10.3 leased
Published Apr 6, 2026
·Updated
Affected Software
1 affected component
OpenSSH OpenSSH<10.3
Frequently Asked Questions
1
What is the severity of CVE-2026-12345?
The severity of CVE-2026-12345 is classified as high due to the potential for shell metacharacter expansion vulnerabilities.
2
How do I fix CVE-2026-12345?
To fix CVE-2026-12345, upgrade to the latest version of OpenSSH 10.3 or later which addresses the metacharacter validation issue.
3
What systems are affected by CVE-2026-12345?
CVE-2026-12345 affects all configurations of OpenSSH that utilize shell metacharacters in user names through command-line input.
4
What impact can CVE-2026-12345 have on my system?
Exploitation of CVE-2026-12345 can lead to unauthorized command execution and potential system compromise.
5
When was CVE-2026-12345 published?
CVE-2026-12345 was published on April 6, 2026.