VulnerabilityAnalyzed
CVE-2026-73281
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
LOW 3.5EPSS 0.16%
Does this matter?
Lower severity and a low EPSS score (0.16%). Track it; it rarely justifies an emergency change on its own.
Description
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
- CVSS 3.1
- 3.5 LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
- EPSS
- 0.16% probability · 5th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-669
- Affected
- openbsd/openssh
- Source
- cve@mitre.org
References
- https://www.openssh.org/releasenotes.html#10.5Product, Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.