In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:12389 https://access.redhat.com/errata/RHSA-2026:12389
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:13380 https://access.redhat.com/errata/RHSA-2026:13380
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:13381 https://access.redhat.com/errata/RHSA-2026:13381
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:13383 https://access.redhat.com/errata/RHSA-2026:13383
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:16059 https://access.redhat.com/errata/RHSA-2026:16059