PT-2026-70883 · Openssh+2 · Openssh+2
CVE-2026-73281
·
Published
2026-08-11
·
Updated
2026-09-03
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSH versions prior to 10.5
Description
A misinteraction between agent locking and the
session-bind@openssh.com extension in ssh-agent allows certain operations intended only for local use to be performed remotely. This occurs because a locked agent may reject binding requests, causing forwarded requests to be incorrectly treated as local. This weakens the trust boundary for sensitive operations, such as adding PKCS#11 tokens or using keys that have destination restrictions. Environments that forward agents to jump hosts, build systems, or shared administrative infrastructure are most exposed.Recommendations
Update to OpenSSH version 10.5 or apply a vendor-supplied backport containing the fix.
Audit hosts where
ForwardAgent is enabled, specifically CI runners, ephemeral builders, and privileged bastions.
Inventory destination-constrained keys to ensure they are used only with patched agents and hosts.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Openssh
Ubuntu