Improper access control in OpenSSH - CVE-2026-73283

 

Improper access control in OpenSSH - CVE-2026-73283

Published: September 3, 2026


Vulnerability identifier: #VU146883
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-73283
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass forwarding restrictions.

The vulnerability exists due to improper access control in sshd authorized_keys restrict keyword enforcement when handling tunnel forwarding. A remote user can use tunnel forwarding despite intended restrictions to bypass forwarding restrictions.

Tunnel forwarding is administratively disabled by default.


Affected software

OpenSSH
Ubuntu
openssh (Ubuntu package)

How to mitigate CVE-2026-73283

Install security update from vendor's website.

OpenSSH - update to 10.5p1
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.17, 1:9.6p1-3ubuntu13.19, 1:10.2p1-2ubuntu3.6

External References

Related Security Bulletins