Use of a broken or risky cryptographic algorithm in Paramiko - CVE-2026-44405

 

Use of a broken or risky cryptographic algorithm in Paramiko - CVE-2026-44405

Published: May 20, 2026


Vulnerability identifier: #VU131979
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2026-44405
CWE-ID: CWE-327
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to modify data on the system.

The vulnerability exists due to the use of a broken or risky cryptographic algorithm. An adjacent attacker can gain unauthorized access to modify data on the system.


Affected software

Paramiko
Storage Virtualize Ansible Collection
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Public Cloud Module
Python 3 Module
openSUSE Leap
IBM Cloud Pak for Data System
python-paramiko-doc
python311-paramiko

How to mitigate CVE-2026-44405

Install updates from vendor's website.

Paramiko - update to a448945
IBM Cloud Pak for Data System - update to 8.10.26.06.SP2
python-paramiko-doc - update to 3.4.0-150400.13.13.1
python311-paramiko - addressed in versions 3.4.0-150400.13.13.1, 3.5.1-150700.20.6.1

External References

Related Security Bulletins