Improper Certificate Revocation Check in mwiede jsch by jcraft
CVE-2026-86231
Key Information:
Badges
What is CVE-2026-86231?
A vulnerability has been identified in mwiede jsch versions up to 2.28.5 related to the function getRevokedKeys found in the KnownHosts.java file. This flaw allows attackers to manipulate the argument known_hosts, resulting in an improper verification process for certificate revocation. The remote exploitation of this vulnerability is possible, although it requires significant complexity to execute. With details of the exploit publicly available, it is crucial for users to upgrade to version 2.28.6, which contains a patch addressing this issue (commit 194a2f76a5c0f1c3f778565be3fd66bcafc42d23).
Affected Version(s)
jsch 2.28.0
jsch 2.28.1
jsch 2.28.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
