CVE-2026-106586: Low severity OpenSSH OpenSSH vulnerability
Published Oct 6, 2026
·Updated
In sshd in OpenSSH before 10.6, the restrict keyword (in authorizedkeys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.
Affected Software
1 affected component
OpenSSH OpenSSH<10.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenSSHto a version that resolves this vulnerability.Fixed in 10.6
Event History
Oct 6, 2026
CVE Published
via MITRE·08:57 PM
Data Sourced
via MITRE·08:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
OpenSSH sshd versions before 10.6 are affected where the restrict keyword in authorized_keys is relied on to restrict tunnel forwarding.
2
What access and conditions are indicated for exploitation?
The supplied CVSS vector indicates local access, low privileges, and high attack complexity. The documented impact is limited to integrity; no confidentiality or availability impact is indicated.
3
Which version should be used to remediate this issue?
Upgrade OpenSSH to version 10.6 or later. The issue is described as affecting versions before 10.6.