Skip to content

H3-2026-0007

SSH ControlMaster Socket Abuse

Category SECURITY_MISCONFIGURATION
Base Score 8.0

Description

A live SSH ControlMaster socket was found on the host, allowing an attacker to reuse an existing authenticated SSH tunnel to reach a remote system without any credentials.

Impact

An attacker with access to the host can hijack the SSH ControlMaster socket to execute commands on the remote system as the connected user, enabling lateral movement without credentials.

References