CVE-2026-73283
Description
A flaw was found in OpenSSH's sshd component. The restrict keyword, designed to limit tunnel forwarding within the authorized_keys file, was not correctly enforced for tunnel forwarding. This issue could allow a local attacker to bypass intended security restrictions, potentially leading to unauthorized network access or resource usage through tunnels.
Statement
An authorization bypass flaw was found in OpenSSH's sshd daemon. When processing SSH public key authentication, sshd fails to enforce the restrict keyword in authorized_keys against TUN/TAP tunnel forwarding requests. An authenticated user holding a restricted key can still establish virtual network interface tunnels if tunnel forwarding is globally enabled on the server. This allows authorized users to bypass intended per-key restriction policies, posing a Moderate impact to confidentiality and integrity.
Mitigation
Set PermitTunnel no in /etc/ssh/sshd_config to disable TUN/TAP tunnel forwarding server-wide. Alternatively, restrict tunnel permissions for specific users or groups using Match blocks in sshd_config or explicit no-tun directives in authorized_keys.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.4 | N/A | 2.5 |
| Attack Vector | Network | N/A | Local |
| Attack Complexity | Low | N/A | High |
| Privileges Required | Low | N/A | Low |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | Low | N/A | None |
| Integrity Impact | Low | N/A | Low |
| Availability Impact | None | N/A | None |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
cve.org: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Understanding the Weakness (CWE)
Access Control
Technical Impact: Bypass Protection Mechanism
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.