CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands
Cybersecurity Classified by Officially
CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands
Bulletin ID: 2026-071-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/03/2026 12:30 PM PDT
AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. We identified CVE-2026-18654, an issue where the EMR SSH helper commands (aws emr ssh, aws emr socks, aws emr put, aws emr get) disabled SSH host key verification, which might allow man-in-the-middle actors to intercept SSH sessions and file transfers via network positioning between the client and the EMR cluster endpoint.
This issue has been addressed in AWS CLI v1 version 1.45.28 and AWS CLI v2 version 2.35.3. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
There is no workaround. The insecure SSH option was hardcoded and could not be overridden by the user. Customers must upgrade to the fixed versions.
We would like to thank Ali Sunbul for collaborating on this issue through the coordinated vulnerability disclosure process.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-071-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 18, 2026 09:42
- Versions
- 1 recorded
- Identity
f1c4173f21cec8d180f23cce4ab92e524f4fdc66