A vulnerability, which was classified as critical, was found in Erlang OTP. Impacted is an unknown function in the library lib/ssh/src/ssh_sftpd.erl of the component ssh_sftpd. Such manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-23942. The attack may be performed from remote. There is no available exploit.