CVE-2026-73281
published 2026-08-11CVE-2026-73281: In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use…
PriorityP414low3.5CVSS 3.1
AVNACHPRLUINSCCNILAN
EPSS
0.16%
5.3th percentile
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the [email protected] extension.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | openssh | < 10.5 | 10.5 |
| openbsd | openssh | — | — |
| ubuntu | openssh | — | — |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
vendor_redhat3.5LOW
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2026-09-03·CVSS 3.5
CVE-2026-73281 [LOW] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH's ssh-agent incorrectly handled interactions
between agent locking and the [email protected] extension. A remote
attacker with access to a forwarded agent connection could possibly use
this issue to perform operations that should only be available locally,
such as adding tokens or using keys. (CVE-2026-73281)
It was discovered that OpenSSH's ssh client incorrectly handled concurrent
remote-forwarding operations. A remote attacker could possibly use this
issue to cause a use-after-free condition, resulting in a denial of service
or the execution of arbitrary code. (CVE-2026-73282)
It was discovered that OpenSSH's sshd server incorrectly applied the
restrict keywor
Red Hat
openssh: OpenSSH: ssh-agent allows remote execution of local operations
vendor_redhat·2026-08-11·CVSS 3.5
CVE-2026-73281 [LOW] CWE-266 openssh: OpenSSH: ssh-agent allows remote execution of local operations
openssh: OpenSSH: ssh-agent allows remote execution of local operations
A flaw was found in OpenSSH's `ssh-agent` component. A misinteraction between agent locking and the `[email protected]` extension allows operations intended for local execution to be performed remotely. This could enable a remote attacker to add PKCS#11 tokens or utilize keys with destination restrictions, bypassing intended security controls.
Statement: Red Hat has determined that this vulnerability has limited impact. Exploitation requires an authenticated SSH session with agent forwarding enabled and the agent in a locked state. Only OpenSSH versions 8.9 and later contain the vulnerable [email protected] extension code. Red Hat Enterprise Linux 6, 7, 8, and RHEL 9 through 9.6 ship OpenSSH versions pr
GHSA
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
ghsa_unreviewed·2026-08-11
CVE-2026-73281 [LOW] CWE-669 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the [email protected] extension.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-73281 openssh: OpenSSH: ssh-agent allows remote execution of local operations [fedora-all]
bugzilla·2026-08-12·CVSS 3.5
CVE-2026-73281 [LOW] CVE-2026-73281 openssh: OpenSSH: ssh-agent allows remote execution of local operations [fedora-all]
CVE-2026-73281 openssh: OpenSSH: ssh-agent allows remote execution of local operations [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the [email protected] extension.
Bugzilla
CVE-2026-73281 openssh: OpenSSH: ssh-agent allows remote execution of local operations
bugzilla·2026-08-11·CVSS 3.5
CVE-2026-73281 [LOW] CVE-2026-73281 openssh: OpenSSH: ssh-agent allows remote execution of local operations
CVE-2026-73281 openssh: OpenSSH: ssh-agent allows remote execution of local operations
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the [email protected] extension.
2026-08-11
Published