CVE-2026-73281

Published Aug 11, 2026

Last updated 2 days ago

Overview

Description
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
Source
cve@mitre.org
NVD status
Analyzed
Products
openssh

Risk scores

CVSS 3.1

Type
Secondary
Base score
3.5
Impact score
1.4
Exploitability score
1.8
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Severity
LOW

Weaknesses

cve@mitre.org
CWE-669

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.