VDB
CVE-2026-73281
CVE-2026-73281
PUBLISHED
CVSS 3.5 LOW
Reported by mitre · Published August 11, 2026
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
Risk Scores
CVSS 3.1
3.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OpenBSD | OpenSSH | 0 |
| OpenBSD | OpenSSH | 0 |
| openbsd | openssh | 0 |
| alpine | openssh | 0, 0, 0 |
Timeline
- Aug 11, 2026 CVE Published
- Aug 11, 2026 CVE Updated
- Aug 12, 2026 Coalition ESS Score
- Aug 14, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 27, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 21, 2026 Distribution Patch
- Sep 21, 2026 Security Advisory