CVE-2026-73281
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the [email protected] extension.
Scoring
- Severity
- LOW
- CVSS base score
- 3.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
- EPSS probability
- 0.16%
- CWE
- CWE-669
- Published
- 2026-08-11
- Last modified
- 2026-08-11
Affected products
- OpenBSD OpenSSH
Weakness type
Related vulnerabilities
- CVE-2026-87724 — Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which...
- CVE-2026-86144 — In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not...
- CVE-2026-75010 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password...
- CVE-2026-75003 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute...
- CVE-2026-75000 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the...
- CVE-2026-73574 — In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the...
- CVE-2026-71194 — In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving...
- CVE-2026-46448 — In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The...