In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

Project Subscriptions

Vendors Products
Openbsd Subscribe
Openssh Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4584-1 openssh security update
Ubuntu USN Ubuntu USN USN-8222-1 OpenSSH vulnerabilities
Ubuntu USN Ubuntu USN USN-8514-1 OpenSSH vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:12389 cve-icon
https://access.redhat.com/errata/RHSA-2026:13380 cve-icon
https://access.redhat.com/errata/RHSA-2026:13381 cve-icon
https://access.redhat.com/errata/RHSA-2026:13383 cve-icon
https://access.redhat.com/errata/RHSA-2026:14937 cve-icon
https://access.redhat.com/errata/RHSA-2026:16059 cve-icon
https://access.redhat.com/errata/RHSA-2026:19069 cve-icon
https://access.redhat.com/errata/RHSA-2026:19219 cve-icon
https://access.redhat.com/errata/RHSA-2026:20040 cve-icon
https://access.redhat.com/errata/RHSA-2026:21275 cve-icon
https://access.redhat.com/errata/RHSA-2026:21298 cve-icon
https://access.redhat.com/errata/RHSA-2026:21398 cve-icon
https://access.redhat.com/errata/RHSA-2026:22329 cve-icon
https://access.redhat.com/errata/RHSA-2026:22468 cve-icon
https://access.redhat.com/errata/RHSA-2026:22564 cve-icon
https://access.redhat.com/errata/RHSA-2026:22648 cve-icon
https://access.redhat.com/errata/RHSA-2026:25044 cve-icon
https://access.redhat.com/errata/RHSA-2026:25063 cve-icon
https://access.redhat.com/errata/RHSA-2026:25096 cve-icon
https://access.redhat.com/errata/RHSA-2026:25181 cve-icon
https://access.redhat.com/errata/RHSA-2026:26528 cve-icon
https://access.redhat.com/errata/RHSA-2026:26542 cve-icon
https://access.redhat.com/errata/RHSA-2026:28887 cve-icon
https://access.redhat.com/errata/RHSA-2026:28962 cve-icon
https://access.redhat.com/errata/RHSA-2026:30078 cve-icon
https://access.redhat.com/errata/RHSA-2026:30087 cve-icon
https://access.redhat.com/errata/RHSA-2026:30088 cve-icon
https://access.redhat.com/errata/RHSA-2026:30089 cve-icon
https://access.redhat.com/errata/RHSA-2026:34098 cve-icon
https://access.redhat.com/security/cve/CVE-2026-35385 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2454469 cve-icon
https://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2 cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-35385 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35385.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-35385 cve-icon
https://www.openssh.org/releasenotes.html#10.3p1 cve-icon cve-icon cve-icon
https://www.openwall.com/lists/oss-security/2026/04/02/3 cve-icon cve-icon cve-icon
History

Sat, 04 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
Title Setuid/Setgid Elevation via scp in OpenSSH <10.3 OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode
References
Metrics threat_severity

None

threat_severity

Important


Fri, 03 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Title Setuid/Setgid Elevation via scp in OpenSSH <10.3

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
First Time appeared Openbsd
Openbsd openssh
Weaknesses CWE-281
CPEs cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Vendors & Products Openbsd
Openbsd openssh
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-15T01:02:53.615Z

Reserved: 2026-04-02T16:30:59.107Z

Link: CVE-2026-35385

cve-icon Vulnrichment

Updated: 2026-07-10T12:05:55.215Z

cve-icon NVD

Status : Modified

Published: 2026-04-02T17:16:27.450

Modified: 2026-07-24T21:10:00.143

Link: CVE-2026-35385

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-02T16:30:59Z

Links: CVE-2026-35385 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-03T09:18:32Z

Weaknesses