CVE-2026-18654
MEDIUM
6,9
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,8
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: none
Availability: none
Description
AI Translation Available
Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint.
To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.
322
Key Exchange without Entity Authentication
DraftCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Applicable Platforms
All platforms may be affected
https://aws.amazon.com/security/security-bulletins/2026-071-aws/
https://github.com/aws/aws-cli/blob/develop/CHANGELOG.rst
https://github.com/aws/aws-cli/blob/v2/CHANGELOG.rst
https://github.com/aws/aws-cli/security/advisories/GHSA-hqvf-45jj-mccq