Back

LOW

openssh: OpenSSH: ssh-agent allows remote execution of local operations

Published Aug 11, 2026

Description

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

Affected products

Remediation

Red Hat statement

Red Hat has determined that this vulnerability has limited impact. Exploitation requires an authenticated SSH session with agent forwarding enabled and the agent in a locked state. Only OpenSSH versions 8.9 and later contain the vulnerable session-bind@openssh.com extension code. Red Hat Enterprise Linux 6, 7, 8, and RHEL 9 through 9.6 ship OpenSSH versions prior to 8.9 and are not affected. Red Hat may apply this fix in a future update for affected products.

Red Hat mitigation

Avoid using ssh-agent forwarding to untrusted remote hosts, or disable agent forwarding entirely by removing `ForwardAgent yes` from SSH configuration. If agent forwarding is required, avoid locking the agent while forwarded sessions are active.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 11, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Analyzed
Modified Sep 4, 2026
Red Hat
Severity Low
Public date Aug 11, 2026