CVE-2026-18654

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
03/08/2026
Last modified:
04/08/2026

Description

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint.<br /> <br /> <br /> <br /> To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.