In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the [email protected] extension.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssh | Sep 1, 2026 | Aug 11, 2026 |
| Ibm Aix | — | Apply the fix or workaround for openssh_advisory22 | Sep 14, 2026 | Sep 11, 2026 |
| Redhat_linux | — | No solution exists | Aug 13, 2026 | Aug 11, 2026 |
| Ubuntu | — | Upgrade openssh-serverUpgrade openssh-client | Sep 14, 2026 | Sep 3, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 15, 2026 | Aug 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub