Disclosure summary
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
Source-reported weakness categories
CWE-669
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Microsoft Security Updates (CVRF) · 2026-Aug
Open original source · Updated Sep 12, 2026
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.
Microsoft maximum product score: 3.5
| Vendor | Product / association | Version / bounds |
|---|---|---|
| Microsoft update guide | azl3 openssh 9.8p1-9 on Azure Linux 3.0 | (MSRC status code 3) |
| Microsoft update guide | azl3 openssh 9.8p1-10 on Azure Linux 3.0 | (MSRC status code 3) |
Vendor remediation references
- Vendor guidance · build 9.8p1-10 · product IDs 21837-17084
- Vendor guidance · product IDs 21837-17084
Original records & references
- NIST NVD record
- CVE Program record
- msrc.microsoft.com — Vendor advisory
PUBLISHED 2026-08-14T14:45:20-04:00
MODIFIED 2026-09-12T21:47:27-04:00
INGESTED 2026-10-08T12:35:48-04:00