Input validation error in Apache Mina SSHD - CVE-2026-58624
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to write files on the server.
The vulnerability exists due to improper input validation in GitPgmCommandFactory in sshd-git when executing JGit commands over SSH. A remote user can invoke a JGit command with crafted arguments to write files on the server.
Only SSH servers using the GitPgmCommandFactory are vulnerable.
Affected software
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
apache-sshd
How to mitigate CVE-2026-58624
apache-sshd - update to 2.19.0-150200.5.16.1