LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-56624

apache · mina sshd

Published
CVSS7.3
Severityhigh
WeaknessCWE-295
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Description

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the certificate, nor did it validate these options. As a result it was possible that a user could authenticate with such a certificate that included a force-command option but still was able to execute other commands. What other command exactly would be available to the user depends on the implementation of the server. This issue is fixed in Apa

References

← Back to the CVE Tracker

Our coverage of CVE-2026-56624

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-56624.