CVE-2026-32147 Details
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to modify file attributes outside the configured chroot directory. The SFTP daemon (ssh_sftpd) stores the raw, user-supplied path in file handles instead of the chroot-resolved path. When SSH_FXP_FSETSTAT is issued on such a handle, file attributes (permissions, ownership, timestamps) are modified on the real filesystem path, bypassing the root directory boundary entirely. Any authenticated SFTP user on a server configured with the root option can modify file attributes of files outside the intended chroot boundary. The prerequisite is that a target file must exist on the real filesystem at the same relative path. Note that this vulnerability only allows modification of file attributes; file contents cannot be read or altered through this attack vector. If the SSH daemon runs as root, this enables direct privilege escalation: an attacker can set the setuid bit on any binary, change ownership of sensitive files, or make system configuration world-writable. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routines ssh_sftpd:do_open/4 and ssh_sftpd:handle_op/4. This issue affects OTP from OTP 17.0 before OTP 28.4.3, OTP 27.3.4.11 and OTP 26.2.5.20, corresponding to ssh from 3.0.1 before 5.5.3, 5.2.11.7 and 5.1.4.15.
A path traversal vulnerability has been identified in the SSH SFTP server component of Erlang OTP. This vulnerability allows authenticated SFTP users to modify file attributes outside of the designated chroot directory. The issue arises because the SFTP daemon (ssh_sftpd) records the original, user-provided file paths in handles, rather than paths adjusted for chroot. As a result, when the SSH_FXP_FSETSTAT command is used, file attributes such as permissions, ownership, and timestamps are changed on the actual filesystem, completely bypassing the chroot restriction. This vulnerability only affects versions of Erlang OTP from 17.0 up to 28.4.3, as well as specific 27 and 26 versions. If the SSH daemon is running as root, this vulnerability can be exploited to escalate privileges by allowing an attacker to manipulate sensitive files or binaries.
Users can mitigate this vulnerability by not using the 'root' option in the SFTP subsystem configuration, and instead relying on OS-level chroot or container isolation. Additionally, the Erlang VM should be run as an unprivileged user to limit the potential impact of any attribute modifications.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cna.erlef.org/cves/CVE-2026-32147.html | EEF | Vendor Advisory |
| https://github.com/erlang/otp/commit/28c5d5a6c5f873dc701b597276271763e7d1c004 | EEF | Patch |
| https://github.com/erlang/otp/security/advisories/GHSA-28jg-mw9x-hpm5 | EEF | Vendor Advisory |
| https://osv.dev/vulnerability/EEF-CVE-2026-32147 | EEF | Third Party Advisory |
| https://www.erlang.org/doc/system/versions.html#order-of-versions | EEF | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | EEF |
Affected Products
| Product | Versions |
|---|---|
| erlang erlang/otp | >= 17.0, < 26.2.5.20 >= 27.0, < 27.3.4.11 >= 28.0, < 28.4.3 |
CPE
Remediation
| |
| erlang erlang/ssh | >= 3.0.1, < 5.1.4.15 >= 5.2, < 5.2.11.7 >= 5.5, < 5.5.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Modified | EEF |
| Jun 17, 2026 | CVE Modified | EEF |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | Reanalysis | [email protected] |
| May 21, 2026 | Initial Analysis | [email protected] |
| Apr 21, 2026 | New CVE Received | EEF |