PT-2026-86576 · Mwiede · Jsch

·

CVE-2026-86231

·

Published

2026-09-06

·

Updated

2026-09-07

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions mwiede jsch versions prior to 2.28.6
Description A security flaw exists in the getRevokedKeys() function within the src/main/java/com/jcraft/jsch/KnownHosts.java file. A remote attacker can manipulate the known hosts argument to cause an improper check for certificate revocation. This attack is characterized by high complexity and is difficult to exploit.
Recommendations Upgrade to version 2.28.6.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86231

Affected Products

Jsch