CVE-2026-106589: OpenBSD OpenSSH

Low severity, CVSS 2.9. EPSS: 0.1% chance of exploitation in the next 30 days.

In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY devices.

Affected products

  • OpenBSD OpenSSH: up to and including 10.6

Published 2026-10-06. Last modified 2026-10-07.