Vulnerability record · CVE-2026-106583 · published 7 October 2026
CVE-2026-106583: In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.
In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.
Description
In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
References
Track CVE-2026-106583 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2026-106583), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.