CVE-2026-56452
CVE-2026-56452 is a high-severity vulnerability in Apache Mina Sshd with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 1% (45th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-22
- Affected product: Apache Mina Sshd
- Published:
- Last modified:
Description
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places. The issue affects only * applications that use no longer supported Apache MINA SSHD versions < 2.0.0 and use the SCP functions to receive files, * or applications using sshd-scp in Apache MINA SSHD >= 2.0.0 to receive files. Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected. The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.
Frequently asked questions
- What is CVE-2026-56452?
- Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places. The issue affects only * applications that use no longer supported Apache MINA SSHD versions < 2.0.0 and use the SCP functions to receive files, * or applications using sshd-scp in Apache MINA SSHD >= 2.0.0 to receive files. Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected. The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.
- How severe is CVE-2026-56452?
- CVE-2026-56452 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2026-56452 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (45th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-56452?
- CVE-2026-56452 primarily affects Apache Mina Sshd. In total, 5 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-56452?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-56452 published?
- CVE-2026-56452 was published on 2026-07-20 and last updated on 2026-07-27.
References
- https://lists.apache.org/thread/xgoqvmksmd94fsqnzqjdtfjxf35os9no
- http://www.openwall.com/lists/oss-security/2026/07/20/15
Affected products (5)
- cpe:2.3:a:apache:mina_sshd:*:*:*:*:*:*:*:*
- cpe:2.3:a:apache:mina_sshd:3.0.0:m1:*:*:*:*:*:*
- cpe:2.3:a:apache:mina_sshd:3.0.0:m2:*:*:*:*:*:*
- cpe:2.3:a:apache:mina_sshd:3.0.0:m3:*:*:*:*:*:*
- cpe:2.3:a:apache:mina_sshd:3.0.0:m4:*:*:*:*:*:*
More vulnerabilities in Apache Mina Sshd
- CVE-2026-56624 — High (CVSS 7.3): Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side…
- CVE-2026-56623 — High (CVSS 7.1): Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side…
- CVE-2026-48827 — High (CVSS 7.1): Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack,…
- CVE-2024-41909 — Medium (CVSS 5.9): Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as…
- CVE-2019-6111 — Medium (CVSS 5.9): An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses…
- CVE-2026-58624 — Medium (CVSS 5.4): Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and…
All CVEs affecting Apache Mina Sshd →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.