CVE-2026-18654

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint. To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.

Scoring

Severity
MEDIUM
CVSS base score
6.9
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
EPSS probability
0.29%
CWE
CWE-322
Published
2026-08-03
Last modified
2026-08-04

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs