CVE-2026-106586
2.5
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Summary
In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenBSD | OpenSSH | 0 < 10.6 | affected |
Weaknesses
- CWE-670: CWE-670 Always-Incorrect Control Flow Implementation
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.