Improper Authorization in OpenSSH - CVE-2026-35388
Published: April 29, 2026
OpenSSH
OpenSSH
Description
The vulnerability allows a local user to bypass connection multiplexing confirmation.
The vulnerability exists due to improper access control in ssh(1) when handling proxy mode multiplexing sessions requested with ssh -O proxy under ControlMaster ask or autoask. A local user can initiate a proxy mode multiplexing session to bypass connection multiplexing confirmation.
The issue is limited to proxy mode multiplexing sessions.