Path Traversal Vulnerability in Apache MINA SSHD for SSH File Transfers
CVE-2026-56452

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
20 July 2026

What is CVE-2026-56452?

A security flaw has been identified in the sshd-scp component of Apache MINA SSHD, a Java library used for SSH communication. The vulnerability arises from the failure to validate filenames in SCP commands, allowing a malicious sender to manipulate file paths. Consequently, this could result in files being written to unauthorized locations within the server. The issue specifically impacts applications that utilize unsupported versions of Apache MINA SSHD before 2.0.0, as well as those employing the sshd-scp functionality in versions 2.0.0 and upwards. To mitigate risks, upgrading to Apache MINA versions 2.19.0 or 3.0.0-M5 is strongly recommended.

Affected Version(s)

Apache MINA SSHD 0 <= 2.18.0

Apache MINA SSHD 3.0.0-M1 <= 3.0.0-M4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Unbbal
.