CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands

Amazon Web Services Version 1 original current

Imported from official source

Bulletin ID: 2026-071-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:30 PM PDT Description: AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. We identified CVE-2026-18654, an issue where the EMR SSH helper commands (aws emr ssh, aws emr socks, aws emr put, aws emr get) disabled SSH host key verification, which might allow man-in-the-middle actors to intercept SSH sessions and file transfers via network positioning between the client and the EMR cluster endpoint. Impacted versions: - AWS CLI v1 <= 1.45.27 - AWS CLI v2 <= 2.35.2 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

This version

Version
1 of 1
Recorded
September 18, 2026 09:42
Change
Initial
Content hash
93fa091b860593139ab3ecf7b5436774
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.