CVE-2026-55655
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is
CVSS
5.0
Medio
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Publicado: 23 jun 2026 · Última mod.: 25 ago 2026 · CWE-923
0.1%EPSS · 30 días0.1%
2026-08-022026-08-30
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36759
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:47755
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:47756
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:47757
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:54387
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:58981
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-55655
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2462250
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-628368.7 ALT36.3%
——11Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.19dCVE-2026-186556.5 MED16.5%
——5Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.
To remediate this issue, users should upgrade to version 2.0.24.27dCVE-2026-239047.3 ALT42.4%
——13Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior.
This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0.
Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.26dCVE-2026-632265.8 MED31.3%
——9Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.39dCVE-2026-8920—1.5%
——0Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable .
Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.47dCVE-2026-598417.5 ALT14.3%
——4A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>47d