Impact
In OpenSSH versions prior to 10.6 the restrict keyword that appears in authorized_keys is intended to prevent users from creating tunnel forwarding streams, yet it does not affect tunnel forwarding, allowing a user whose key contains restrict to open SSH tunnels that were supposed to be blocked, which enables unauthorized lateral movement and exposure of internal services but does not provide code execution or privilege escalation.
Affected Systems
OpenBSD OpenSSH installations running a version earlier than 10.6 are affected; no specific sub‑version information is provided beyond the cutoff, so administrators must verify their running version.
Risk and Exploitability
The CVSS score of 2.5 indicates a low impact, the EPSS score is not available and the vulnerability is not listed in CISA KEV; the likely attack vector is a legitimate SSH login where the attacker uses a key with the restrict keyword but still opens a tunnel, requiring only authentication as a user and enabling unauthorized forwarding.
OpenCVE Enrichment