---
id: CVE-2026-73281
title: >-
  In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but
  were intended to occur only locally, including operations that add tokens or
  use keys
summary: >-
  In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but
  were intended to occur only locally, including operations that add tokens or
  use keys. This is caused by misinteraction between agent locking and the
  session-bin…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-669
  - CWE-266
vendor: openbsd
product: openssh
affected:
  - openssh < 10.5
patched:
  - openssh 10.5
published: '2026-08-11'
updated: '2026-09-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73281'
references:
  - url: 'https://www.openssh.org/releasenotes.html#10.5'
    label: cve@mitre.org
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73281.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-73281'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2514327'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-73281'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73281'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69129'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69130'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70719'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00158
epssPercentile: 0.05394
ingestedAt: '2026-09-05T15:41:16.667Z'
---

## Overview

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

## Affected

- `openssh < 10.5`

## Remediation

Upgrade past the affected range:

- `openssh 10.5`

## Vendor advisories

- **RHSA-2026:69129** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69129)
- **Red Hat VEX** · Low · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73281.json)
- **RHSA-2026:69130** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69130)
- **RHSA-2026:70719** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70719)
