CVE-2026-86231
Last modified
CVE-2026-86231 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| mwiede | jsch | 2.28.0; 2.28.1; 2.28.2; 2.28.3; 2.28.4; 2.28.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86231?
How severe is CVE-2026-86231?
How do I fix CVE-2026-86231?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86224A vulnerability was determined in SourceCodester Class and E…7.3
- CVE-2026-86225A vulnerability was identified in SourceCodester Class and E…7.3
- CVE-2026-86226A security flaw has been discovered in Projectwolds Online A…3.5
- CVE-2026-86227A weakness has been identified in valkey-io valkey up to 9.0…3.1
- CVE-2026-86228A security vulnerability has been detected in JeecgBoot up t…4.3
- CVE-2026-8623The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PD…6.4
- CVE-2026-86232A weakness has been identified in itsourcecode Sales and Inv…6.3
- CVE-2026-86233A security vulnerability has been detected in itsourcecode S…6.3
- CVE-2026-86234A vulnerability was detected in itsourcecode Sales and Inven…6.3
- CVE-2026-86235A flaw has been found in itsourcecode Sales and Inventory Sy…6.3
- CVE-2026-86236A vulnerability has been found in itsourcecode Sales and Inv…6.3
- CVE-2026-86237A vulnerability was found in openagents-org openagents up to…5.3
Are you affected by CVE-2026-86231?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
