{"id":"CVE-2026-73281","title":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys","summary":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bin…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","cwe":["CWE-669","CWE-266"],"vendor":"openbsd","product":"openssh","affected":["openssh < 10.5"],"patched":["openssh 10.5"],"published":"2026-08-11","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","references":[{"url":"https://www.openssh.org/releasenotes.html#10.5","label":"cve@mitre.org"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73281.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-73281"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514327"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73281"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281"},{"url":"https://access.redhat.com/errata/RHSA-2026:69129"},{"url":"https://access.redhat.com/errata/RHSA-2026:69130"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00158,"epssPercentile":0.05404,"ingestedAt":"2026-09-05T15:41:16.667Z","slug":"CVE-2026-73281","body":"## Overview\n\nIn ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.\n\n## Affected\n\n- `openssh < 10.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openssh 10.5`\n\n## Vendor advisories\n\n- **RHSA-2026:69129** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69129)\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Hardened Images · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73281.json)\n- **RHSA-2026:69130** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69130)","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}