01 Record
CVE-2026-106588
In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.
LowPUBLISHEDCNA: mitre
CNA base score3.1 CVSS v3.xCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
02 Description
In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.
03 Exploitation and scoring
- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- Not scored by EPSS
- EPSS percentile
- Not scored by EPSS
- NVD base score
- The NVD has published no score for this record
- NVD CVSS vector
- No NVD score to derive
- NVD analysis status
- Not recorded
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
04 Metadata
- Published
- 2026-10-06 21:10Z1 HR AGO
- Last updated
- 2026-10-06 21:10Z1 HR AGO
- Reserved
- 2026-10-06
- Assigning CNA
- mitre
- Record state
- PUBLISHED
- Severity
- Low (CVSS 3.1)
- CNA CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weaknesses
- CWE-653Improper Isolation or CompartmentalizationClass
- Data version
- 5.2
- Document digest
- 59513b9887d069f42e37703a1f6fab1662a6dce9af7b9dee4f2786ab83b9e2b4
05 Affected products
VendorProductVersionsPlatforms
06 References
- www.openssh.orghttps://www.openssh.org/releasenotes.html#10.6