CVE-2026-56624
Apache Software Foundation Apache MINA SSHD, mina sshd
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the certificate, nor did it validate these options. As a result it was possible that a user could authenticate with such a certificate that included a force-command option but still was able to execute other commands. What other command exactly would b...
- CVSS
- 7.3
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.21