Man-in-the-Middle Vulnerability in Amazon AWS CLI SSH Helper
CVE-2026-18654

6.9MEDIUM

Key Information:

Vendor

Aws

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-18654?

A vulnerability exists in the EMR SSH helper commands of Amazon AWS CLI, where key exchange can occur without proper entity authentication. This flaw potentially allows man-in-the-middle attackers to intercept SSH sessions and file transfers by exploiting network positioning between the client and the EMR cluster endpoint. To protect against this risk, it is essential for users to upgrade to AWS CLI version 1.45.28 or newer for version 1, or version 2.35.3 or newer for version 2.

Affected Version(s)

aws-cli 0 <= 1.45.27

aws-cli 0 <= 2.35.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.