Sploitus

CVE-2026-35385

1 known exploit for CVE-2026-35385

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

Openbsd Openssh
< 10.3
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
0.6% (47th percentile)
Weakness
CWE-281
NVD status
Modified
Published
2026-04-02
CVE-2026-35385 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-35385

Proof-of-concept code and exploit modules indexed by Sploitus