CVE-2026-32147 | Erlang OTP System Configuration ssh_sftpd.erl path traversal (GHSA-28jg-mw9x-hpm5 / WID-SEC-2026-1224)
A vulnerability identified as critical has been detected in Erlang OTP. This affects an unknown part in the library lib/ssh/src/ssh_sftpd.erl of the component System Configuration Handler. Performing a manipulation results in path traversal.
This vulnerability is reported as CVE-2026-32147. The attack is possible to be carried out remotely. No exploit exists.
Applying a patch is the recommended action to fix this issue.