← Browse

CVE-2026-73281

Low

No strong exploitation signal.

CVSS base
3.5 LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
EPSS — probability of exploitation (30 days)
0.2%
5.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-669
Published 2026-08-11 · modified 2026-09-04

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredLLow
User InteractionNNone
ScopeCChanged
ConfidentialityNNone
IntegrityLLow
AvailabilityNNone

Timeline

Description

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

Affected

openbsd

References

Official: NVD · CVE.org