PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106552 OpenBSD CVE debrief

CVE-2026-106552 is a directory traversal vulnerability in OpenSSH before version 10.6, which can be exploited during a recursive copy operation in sftp. This issue allows a server to write files to unintended locations. The vulnerability has a medium severity and is particularly relevant for system administrators and security teams responsible for OpenSSH installations, especially those using versions prior to 10.6. They should assess exposure and consider upgrading to mitigate this vulnerability. The impact is limited by the need for a specific configuration and action to exploit the vulnerability, but it could lead to potential unauthorized file writes and the need for version 10

Vendor
OpenBSD
Product
OpenSSH
CVSS
MEDIUM 4.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-07
Advisory published
2026-10-06
Advisory updated
2026-10-07

Who should care

System administrators and security teams responsible for OpenSSH installations, especially those using versions prior to 10.6, should assess exposure and consider upgrading to mitigate this vulnerability.

Why it matters

CVE-2026-106552 is a medium-severity vulnerability in OpenSSH that allows a server to write files to unintended locations during a recursive copy operation in sftp. System administrators and security teams should assess exposure, especially for versions prior to 10.6, and consider upgrading to mitigate this vulnerability. The impact is limited by the need for a specific configuration and action to exploit the vulnerability.

  • Potential unauthorized file writes
  • Need for version upgrade or patching
  • Monitoring for suspicious sftp activity

Technical summary

A directory traversal vulnerability exists in OpenSSH before version 10.6. During a recursive copy operation in sftp, a server can trigger directory traversal, potentially causing files to be written to unintended locations. This vulnerability is particularly concerning for OpenSSH users, especially those using versions prior to 10.6, as it could allow for unauthorized file writes. Users should review and restrict sftp access to sensitive areas and monitor OpenSSH logs for suspicious activity. The vulnerability has a CVSS score of 4.2 and a medium severity, and it

Defensive priority

Medium priority for OpenSSH users, especially those using versions prior to 10.6.

Recommended defensive actions

  • Upgrade OpenSSH to version 10.6 or later
  • Review and restrict sftp access to sensitive areas
  • Monitor OpenSSH logs for suspicious activity

Evidence notes

The CVE record and OpenSSH release notes provide information about the vulnerability. However, details about potential exploitation or affected systems are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106552 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106552

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106552 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106552

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-106552

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106552.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.openssh.org/releasenotes.html

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.