Security Flaw in OpenSSH Affecting Tunnel Forwarding in Authorized Keys
CVE-2026-106586

2.5LOW

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106586?

A vulnerability in OpenSSH versions prior to 10.6 affects the intended functionality of the restrict keyword in authorized_keys. This misconfiguration prevents the expected restriction of tunnel forwarding, potentially exposing users to unauthorized access and data interception. Mitigation requires upgrading to the latest version to safeguard against this oversight.

Affected Version(s)

OpenSSH 0 < 10.6

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.