Improper Certificate Validation in Apache Mina SSHD - CVE-2026-56624
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to execute commands outside intended certificate restrictions.
The vulnerability exists due to improper certificate validation in server-side OpenSSH user certificate validation when processing certificate options during user authentication. A remote user can present a crafted certificate containing an unsupported force-command or verify-required option to execute commands outside intended certificate restrictions.
The specific commands available depend on the implementation of the server.
Affected software
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
apache-sshd
How to mitigate CVE-2026-56624
apache-sshd - update to 2.19.0-150200.5.16.1