CVE-2026-56624
Last modified
CVE-2026-56624 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the certificate, nor did it validate these options. As a result it was possible that a user could authenticate with such a certificate that included a force-command option but still was able to execute other commands. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the certificate, nor did it validate these options. As a result it was possible that a user could authenticate with such a certificate that included a force-command option but still was able to execute other commands. What other command exactly would be available to the user depends on the implementation of the server. This issue is fixed in Apache MINA SSHD 2.19.0 and 3.0.0-M5. Applications are advised to upgrade to these versions. The fix rejects OpenSSH user certificates that include these options, since Apache MINA SSHD implements neither force-command nor sk-*-cert-v01@openssh.com user certificates (which are the only ones for which verify-required would make sense).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Mina Sshd | >= 2.0.0, < 2.19.0 | — |
| Apache | Mina Sshd | 3.0.0 | M1 |
References
- https://lists.apache.org/thread/o4c2jml522j3z80gbryqzc2f1253ltp6Vendor Advisory, Mailing List
- http://www.openwall.com/lists/oss-security/2026/07/20/17Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-56624?
How severe is CVE-2026-56624?
How do I fix CVE-2026-56624?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56608HCL iControl is affected by Missing Access Control vulnerabi…5.3
- CVE-2026-56609HCL iControl is affected by Weak SSL/TLS Version Supported v…6.5
- CVE-2026-5661A vulnerability was identified in Free5GC 4.2.0. This affect…5.5
- CVE-2026-56619HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scri…5.4
- CVE-2026-56620HCL BigFix Mobile is vulnerable to information disclosure du…4.3
- CVE-2026-56623Path traversal on Windows in Apache MINA SSHD component sshd…7.1
- CVE-2026-5663A security flaw has been discovered in OFFIS DCMTK up to 3.7…9.8
- CVE-2026-5664Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-56642Stack-based buffer overflow in Microsoft Fabric Data Warehou…8.8
- CVE-2026-56643Use after free in Windows Kernel allows an authorized attack…7.8
- CVE-2026-56644Use after free in Windows Kernel allows an authorized attack…7.8
- CVE-2026-56645Heap-based buffer overflow in Microsoft Edge (Chromium-based…8.8
Are you affected by CVE-2026-56624?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
