In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:12389 https://access.redhat.com/errata/RHSA-2026:12389
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:13380 https://access.redhat.com/errata/RHSA-2026:13380
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:13381 https://access.redhat.com/errata/RHSA-2026:13381
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:13383 https://access.redhat.com/errata/RHSA-2026:13383
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:16059 https://access.redhat.com/errata/RHSA-2026:16059
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19069 https://access.redhat.com/errata/RHSA-2026:19069
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19219 https://access.redhat.com/errata/RHSA-2026:19219
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:21298 https://access.redhat.com/errata/RHSA-2026:21298
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:21398 https://access.redhat.com/errata/RHSA-2026:21398