CVE-2026-86231
CVE-2026-86231 is a low-severity vulnerability with a CVSS 3.x base score of 3.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-298.
Key facts
- Severity: Low (CVSS 3.x base score 3.7)
- CVSS v2: 2.6
- CVSS v4: 2.9
- EPSS exploit prediction: 0% (34th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-298
- Published:
- Last modified:
Description
A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.
Frequently asked questions
- What is CVE-2026-86231?
- A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.
- How severe is CVE-2026-86231?
- CVE-2026-86231 has a CVSS 3.x base score of 3.7, rated low severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-86231 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (34th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-86231?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-86231 published?
- CVE-2026-86231 was published on 2026-09-06 and last updated on 2026-09-11.
References
- https://github.com/mwiede/jsch/
- https://github.com/mwiede/jsch/commit/194a2f76a5c0f1c3f778565be3fd66bcafc42d23
- https://github.com/mwiede/jsch/issues/1091
- https://github.com/mwiede/jsch/pull/1098
- https://github.com/mwiede/jsch/releases/tag/jsch-2.28.6
- https://vuldb.com/cve/CVE-2026-86231
- https://vuldb.com/submit/898485
- https://vuldb.com/vuln/399388
- https://vuldb.com/vuln/399388/cti
Other CWE-298 vulnerabilities
- CVE-2025-67109 — Critical (CVSS 10.0): Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass…
- CVE-2025-67108 — Critical (CVSS 10.0): eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure…
- CVE-2025-61736 — High (CVSS 7.1): Successful exploitation of this vulnerability could result in the product failing to re-establish communication once…
- CVE-2025-4384 — Medium (CVSS 6.0): The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet…
- CVE-2025-59036 — Medium (CVSS 5.5): Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the…
- CVE-2024-1248 — Medium (CVSS 4.8): The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly…