PT-2026-67492 · Amazon · Aws Cli
CVE-2026-18654
·
Published
2026-08-03
·
Updated
2026-08-10
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Amazon AWS CLI versions prior to 1.45.28
Amazon AWS CLI v2 versions prior to 2.35.3
Description
Key exchange without entity authentication in the EMR SSH helper commands allows man-in-the-middle attackers to intercept SSH sessions and file transfers by positioning themselves on the network between the client and the EMR cluster endpoint.
Recommendations
Upgrade Amazon AWS CLI v1 to version 1.45.28 or later.
Upgrade Amazon AWS CLI v2 to version 2.35.3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws Cli