VDB

CVE-2026-73281

CVE-2026-73281 PUBLISHED CVSS 3.5 LOW

Reported by mitre · Published August 11, 2026

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

Risk Scores

CVSS 3.1
3.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N

Affected Products

VendorProductVersions
OpenBSDOpenSSH0
OpenBSDOpenSSH0
openbsdopenssh0
alpineopenssh0, 0, 0

Timeline

  • Aug 11, 2026 CVE Published
  • Aug 11, 2026 CVE Updated
  • Aug 12, 2026 Coalition ESS Score
  • Aug 14, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 27, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 21, 2026 Distribution Patch
  • Sep 21, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›