Improper Certificate Revocation Check in mwiede jsch by jcraft
CVE-2026-86231

6.3MEDIUM

Key Information:

Vendor

Mwiede

Status
Vendor
CVE Published:
6 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-86231?

A vulnerability has been identified in mwiede jsch versions up to 2.28.5 related to the function getRevokedKeys found in the KnownHosts.java file. This flaw allows attackers to manipulate the argument known_hosts, resulting in an improper verification process for certificate revocation. The remote exploitation of this vulnerability is possible, although it requires significant complexity to execute. With details of the exploit publicly available, it is crucial for users to upgrade to version 2.28.6, which contains a patch addressing this issue (commit 194a2f76a5c0f1c3f778565be3fd66bcafc42d23).

Affected Version(s)

jsch 2.28.0

jsch 2.28.1

jsch 2.28.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Bao from PayPal Cyber Security Team (VulDB User)
.