CVE-2026-18654CWE-322

CVE-2026-18654

Medium · published August 4, 2026

CVSS v3.1
6.8
EPSS
0%
Percentile
21.3
In the wild
Unconfirmed
What it is

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint.

To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.

The record
Technical detail
CVSS v3.1
6.8 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00291 · 21.3th percentile
Weakness
CWE-322 · Key Exchange without Entity Authentication
Published
2026-08-04T00:17Z
References (4)
EPSS history
Timeline
  • 03 AUG 19:38Z
    Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
    cvelistv5