CVE-2026-56452
published 2026-07-20CVE-2026-56452: Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.36%
28.4th percentile
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.
The issue affects only
* applications that use no longer supported Apache MINA SSHD versions = 2.0.0 to receive files.
Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected.
The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mina_sshd | — | — |
| apache | mina_sshd | — | — |
| apache | mina_sshd | — | — |
| apache | mina_sshd | — | — |
| apache | mina_sshd | >= 2.0.0 < 2.19.0 | 2.19.0 |
| apache_software_foundation | apache_mina_sshd | <= 2.18.0 | — |
| apache_software_foundation | apache_mina_sshd | 3.0.0-M1 – 3.0.0-M4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache MINA SSHD up to 2.18.0/3.0.0-M4 sshd-scp path traversal
vuldb·2026-07-20·CVSS 7.5
CVE-2026-56452 [HIGH] Apache MINA SSHD up to 2.18.0/3.0.0-M4 sshd-scp path traversal
A vulnerability was found in Apache MINA SSHD up to 2.18.0/3.0.0-M4. It has been declared as critical. Affected is an unknown function of the component sshd-scp. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-56452. The attack may be launched remotely. There is no exploit available.
GHSA
Path traversal in the sshd-scp component of Apache MINA SSHD.
ghsa_unreviewed·2026-07-20
CVE-2026-56452 [HIGH] CWE-22 Path traversal in the sshd-scp component of Apache MINA SSHD.
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places.
The issue affects only
* applications that use no longer supported Apache MINA SSHD versions = 2.0.0 to receive files.
Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected.
The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-20
Published