Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-56624 Details

Description

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the certificate, nor did it validate these options. As a result it was possible that a user could authenticate with such a certificate that included a force-command option but still was able to execute other commands. What other command exactly would be available to the user depends on the implementation of the server. This issue is fixed in Apache MINA SSHD 2.19.0 and 3.0.0-M5. Applications are advised to upgrade to these versions. The fix rejects OpenSSH user certificates that include these options, since Apache MINA SSHD implements neither force-command nor sk-*[email protected] user certificates (which are the only ones for which verify-required would make sense).

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-295Improper Certificate Validation[email protected]

Affected Products

ProductVersions
apache mina sshd
>= 2.0.0, < 2.19.0
3.0.0 m1
3.0.0 m2
3.0.0 m3
3.0.0 m4

CPE

  • cpe:2.3:a:apache:mina_sshd:*:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:mina_sshd:3.0.0:m1:*:*:*:*:*:*
  • cpe:2.3:a:apache:mina_sshd:3.0.0:m2:*:*:*:*:*:*
  • cpe:2.3:a:apache:mina_sshd:3.0.0:m3:*:*:*:*:*:*
  • cpe:2.3:a:apache:mina_sshd:3.0.0:m4:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-56624
NVD Published Date:
Jul 20, 2026
NVD Last Modified:
Jul 27, 2026
Source:
[email protected]
CVE-2026-56624 Details - Not Deferred