Apache · Apache Mina Sshd · CVE-2026-56624
**Name of the Vulnerable Software and Affected Versions**
Apache MINA SSHD versions prior to 2.19.0
Apache MINA SSHD versions prior to 3.0.0-M5
**Description**
Improper certificate validation occurs during server-side OpenSSH user authentication. The server fails to check or validate the `force-command` or `verify-required` options embedded in certificates. This allows a user to authenticate with a certificate containing a `force-command` option and potentially execute commands other than the one specified, depending on the server implementation.
**Recommendations**
Upgrade to version 2.19.0.
Upgrade to version 3.0.0-M5.