2026-071-AWSHigh

CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands

Published
August 3, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Bulletin ID: 2026-071-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:30 PM PDT Description: AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. We identified CVE-2026-18654, an issue where the EMR SSH helper commands (aws emr ssh, aws emr socks, aws emr put, aws emr get) disabled SSH host key verification, which might allow man-in-the-middle actors to intercept SSH sessions and file transfers via network positioning between the client and the EMR cluster endpoint. Impacted versions: - AWS CLI v1 - AWS CLI v2
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

🔗 References (1)