CVE-2026-73281

EUVD-2026-56890
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.5 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.23%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
𝑥
< 10.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
postponed
bookworm (security)
vulnerable
forky
1:10.5p1-1
fixed
sid
1:10.5p1-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
openssh-gssapi
forky
1:10.5p1-1
fixed
sid
1:10.5p1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
bionic
needs-triage
focal
needs-triage
jammy
Fixed 1:8.9p1-3ubuntu0.17
released
noble
Fixed 1:9.6p1-3ubuntu13.19
released
resolute
Fixed 1:10.2p1-2ubuntu3.6
released
trusty
needs-triage
xenial
needs-triage
openssh-ssh1
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
resolute
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssh
RHEL 9
0:9.9p1-11.el9_8
fixed
openssh-askpass
RHEL 9
0:9.9p1-11.el9_8
fixed
openssh-clients
RHEL 9
0:9.9p1-11.el9_8
fixed
openssh-keycat
RHEL 9
0:9.9p1-11.el9_8
fixed
openssh-server
RHEL 9
0:9.9p1-11.el9_8
fixed
pam
RHEL 9
0:0.10.4-8.11.el9_8
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
openssh
Azure Linux 3.0
0:9.8p1-10.azl3
fixed