Bug 2503053 (CVE-2026-56624) - CVE-2026-56624 org.apache.sshd/sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation
Summary: CVE-2026-56624 org.apache.sshd/sshd-core: Apache MINA SSHD: Unauthorized comm...
Keywords:
Status: NEW
Alias: CVE-2026-56624
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-20 21:02 UTC by OSIDB Bzimport
Modified: 2026-08-13 23:28 UTC (History)
63 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:54776 0 None None None 2026-08-13 23:28:29 UTC

Description OSIDB Bzimport 2026-07-20 21:02:10 UTC
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH.




Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the certificate, nor did it validate these options. As a result it was possible that a user could authenticate with such a certificate that included a force-command option but still was able to execute other commands. What other command exactly would be available to the user depends on the implementation of the server.




This issue is fixed in Apache MINA SSHD 2.19.0 and 3.0.0-M5. Applications are advised to upgrade to these versions.




The fix rejects OpenSSH user certificates that include these options, since Apache MINA SSHD implements neither force-command nor sk-*-cert-v01 user certificates (which are the only ones for which verify-required would make sense).

Comment 3 errata-xmlrpc 2026-08-13 23:28:25 UTC
This issue has been addressed in the following products:

  Red Hat Build of Apache Camel 4.18 for Quarkus 3.33

Via RHSA-2026:54776 https://access.redhat.com/errata/RHSA-2026:54776


Note You need to log in before you can comment on or make changes to this bug.