https://seclists.org/oss-sec/2026/q2/26: Announce: OpenSSH 10.3 leased
Published Apr 6, 2026
·Updated
Affected Software
1 affected component
OpenSSH OpenSSH<10.3
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is currently classified as medium due to the potential for command injection vulnerabilities.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, users should upgrade to OpenSSH version 10.3 or later.
3
What impact does CVE-2026-XXXX have on OpenSSH users?
CVE-2026-XXXX may allow an attacker to execute arbitrary commands through improperly validated shell metacharacters.
4
What are the affected configurations in CVE-2026-XXXX?
The affected configurations in CVE-2026-XXXX involve the use of user names with shell metacharacters on the command line that are incorrectly processed.
5
When was CVE-2026-XXXX discovered?
CVE-2026-XXXX was publicly announced on April 6, 2026.