High severity7.5NVD Advisory· Published Apr 2, 2026· Updated Apr 27, 2026
CVE-2026-35385
CVE-2026-35385
Description
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- marc.infonvdThird Party Advisory
- www.openwall.com/lists/oss-security/2026/04/02/3nvdThird Party Advisory
- www.openssh.org/releasenotes.htmlnvdRelease Notes
News mentions
0No linked articles in our index yet.