Remote Operation Vulnerability in OpenSSH Affecting Multiple Versions
CVE-2026-73281
3.5LOW
What is CVE-2026-73281?
A security issue exists in OpenSSH where certain operations that should only be performed locally can unintentionally occur remotely. This vulnerability arises from the improper interaction between the agent locking mechanism and the session-bind@openssh.com extension, potentially exposing sensitive tokens and keys. Users are advised to upgrade to OpenSSH version 10.5 or later to mitigate this risk.
Affected Version(s)
OpenSSH 0 < 10.5