CVE Vulnerabilities

CVE-2026-35386

Incorrect Behavior Order

Published: Apr 02, 2026 | Modified: Apr 27, 2026
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
3.6 LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

Weakness

The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.

Affected Software

NameVendorStart VersionEnd Version
OpensshOpenbsd*10.3 (excluding)
Red Hat Enterprise Linux 10RedHatopenssh-0:9.9p1-14.el10_1*
Red Hat Enterprise Linux 10RedHatopenssh-0:9.9p1-23.el10_2*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatopenssh-0:9.9p1-7.el10_0.3*
Red Hat Enterprise Linux 8RedHatopenssh-0:8.0p1-29.el8_10*
Red Hat Enterprise Linux 8RedHatopenssh-0:8.0p1-29.el8_10*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatopenssh-0:8.0p1-7.el8_4.2*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatopenssh-0:8.0p1-7.el8_4.2*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatopenssh-0:8.0p1-15.el8_6.5*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatopenssh-0:8.0p1-15.el8_6.5*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatopenssh-0:8.0p1-15.el8_6.5*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatopenssh-0:8.0p1-20.el8_8.4*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatopenssh-0:8.0p1-20.el8_8.4*
Red Hat Enterprise Linux 9RedHatopenssh-0:8.7p1-49.el9_7*
Red Hat Enterprise Linux 9RedHatopenssh-0:9.9p1-7.el9_8*
Red Hat Enterprise Linux 9RedHatopenssh-0:8.7p1-49.el9_7*
Red Hat Enterprise Linux 9RedHatopenssh-0:9.9p1-7.el9_8*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatopenssh-0:8.7p1-30.el9_2.11*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatopenssh-0:8.7p1-38.el9_4.8*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatopenssh-0:8.7p1-45.el9_6.3*
Red Hat AI Inference Server 3.2RedHatrhaiis/model-opt-cuda-rhel9:1780681984*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:1778101579*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1779798165*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1779798222*
OpensshUbuntudevel*
OpensshUbuntuesm-infra/xenial*
OpensshUbuntufips-preview/jammy*
OpensshUbuntufips-updates/jammy*
OpensshUbuntufips-updates/noble*
OpensshUbuntujammy*
OpensshUbuntunoble*
OpensshUbuntuquesting*
OpensshUbunturesolute*
Openssh-ssh1Ubuntudevel*
Openssh-ssh1Ubuntuesm-apps/bionic*
Openssh-ssh1Ubuntuesm-apps/focal*
Openssh-ssh1Ubuntuesm-apps/jammy*
Openssh-ssh1Ubuntuesm-apps/noble*
Openssh-ssh1Ubuntuesm-apps/resolute*
Openssh-ssh1Ubuntujammy*
Openssh-ssh1Ubuntunoble*
Openssh-ssh1Ubuntuquesting*
Openssh-ssh1Ubunturesolute*
Openssh-ssh1Ubuntuupstream*

References