CVE-2026-59999 Details
Description
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
A vulnerability exists in the OpenSSH sshd component, prior to version 10.4, where the 'DisableForwarding=yes' directive did not properly override 'PermitTunnel=yes', contrary to the documentation. This issue could lead to unintended tunneling permissions being granted.
Users can upgrade to OpenSSH version 10.4 or later, where this issue has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2 | [email protected] | Release Notes |
| https://www.openssh.org/releasenotes.html#10.4p1 | [email protected] | Release Notes |
| https://www.openwall.com/lists/oss-security/2026/07/06/5 | [email protected] | Mailing ListRelease Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openbsd openssh | < 10.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |