Description
In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.
Published: 2026-10-06
Score: 2.5 Low
EPSS: n/a
KEV: No
Impact: Unauthorized Port Forwarding
Action: Upgrade
AI Analysis

Impact

In OpenSSH versions prior to 10.6 the restrict keyword that appears in authorized_keys is intended to prevent users from creating tunnel forwarding streams, yet it does not affect tunnel forwarding, allowing a user whose key contains restrict to open SSH tunnels that were supposed to be blocked, which enables unauthorized lateral movement and exposure of internal services but does not provide code execution or privilege escalation.

Affected Systems

OpenBSD OpenSSH installations running a version earlier than 10.6 are affected; no specific sub‑version information is provided beyond the cutoff, so administrators must verify their running version.

Risk and Exploitability

The CVSS score of 2.5 indicates a low impact, the EPSS score is not available and the vulnerability is not listed in CISA KEV; the likely attack vector is a legitimate SSH login where the attacker uses a key with the restrict keyword but still opens a tunnel, requiring only authentication as a user and enabling unauthorized forwarding.

Generated by OpenCVE AI on October 7, 2026 at 00:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenSSH to version 10.6 or later.
  • In the meantime, set AllowTcpForwarding no or adjust PermitOpen restrictions in sshd_config to block unwanted tunnels.
  • Remove or replace the restrict keyword from authorized_keys entries or enforce stricter key policies.

Generated by OpenCVE AI on October 7, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Title OpenSSH restrict keyword ineffective for tunnel forwarding

Tue, 06 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.
First Time appeared Openbsd
Openbsd openssh
Weaknesses CWE-670
CPEs cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Vendors & Products Openbsd
Openbsd openssh
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-06T20:57:09.067Z

Reserved: 2026-10-06T20:57:08.698Z

Link: CVE-2026-106586

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T21:17:19.803

Modified: 2026-10-06T21:17:19.803

Link: CVE-2026-106586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T00:15:07Z

Weaknesses
  • CWE-670

    Always-Incorrect Control Flow Implementation