- Description
- In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- openssh
CVSS 3.1
- Type
- Secondary
- Base score
- 3.5
- Impact score
- 1.4
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
- Severity
- LOW
- cve@mitre.org
- CWE-669
- Hype score
- Not currently trending
状況調べますか… OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース https://t.co/sMAYZg7Dc5
@wakababest
12 Aug 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssh #openssh https://t.co/xKtgb43ZHc
@omokazuki
12 Aug 2026
107 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*",
"matchCriteriaId": "85C0FBF8-1AE6-4A15-A6B2-41B5790E88E1",
"versionEndExcluding": "10.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]