CVE-2026-106583

EUVD-2026-94104
In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.
Resource Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mitreCNA
2.5 LOW
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.12%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
openbsdopenssh
𝑥
< 10.6
CNA
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
vulnerable
bookworm (security)
vulnerable
forky
vulnerable
sid
1:10.6p1-1
fixed
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
openssh-ssh1
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
resolute
ignored
openssh-gssapi
jammy
dne
noble
dne
resolute
dne