CVE-2026-35388 | OpenSSH up to 10.2 Proxy-mode Multiplexing Session unprotected alternate channel (Nessus ID 306743)
A vulnerability was found in OpenSSH up to 10.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Proxy-mode Multiplexing Session Handler. The manipulation results in unprotected alternate channel.
This vulnerability is known as CVE-2026-35388. Attacking locally is a requirement. No exploit is available.
It is suggested to upgrade the affected component.