CVE-2026-73281

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
References
Link Resource
https://www.openssh.org/releasenotes.html#10.5 Product Release Notes
Configurations

Configuration 1 (hide)

cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-11 20:18

Updated : 2026-09-04 16:04


NVD link : CVE-2026-73281

Mitre link : CVE-2026-73281

CVE.ORG link : CVE-2026-73281


JSON object : View

Products Affected

openbsd

  • openssh
CWE
CWE-669

Incorrect Resource Transfer Between Spheres