CVE-2026-77585
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be i
CVSS
5.3
Medio
EPSS
0.1%
p1
KEV
—
Exploit Today
0
0-100
Publicado: 25 ago 2026 · Última mod.: 26 ago 2026 · CWE-78
Sin historial EPSS suficiente todavía.
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-747708.8 ALT—
———Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.2hCVE-2026-688618.8 ALT—
———Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.2hCVE-2026-711717.2 ALT—
———Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.23hCVE-2026-704199.1 CRÍ—
———Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.23hCVE-2026-650866.8 MED63.9%
——19NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.1dCVE-2026-799927.8 ALT2.9%
——1A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.1d