PT-2026-45380 · Apache · Apache Mina Sshd

·

CVE-2026-48827

·

Published

2026-06-01

·

Updated

2026-07-27

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache MINA SSHD versions prior to 2.18.0 Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M3
Description A path traversal issue exists in the org.apache.sshd:sshd-git bundle. Due to insufficient path validation in git-upload-pack, git-receive-pack, and other git operations, users authenticated via SSH can access git repositories located outside the configured git server root directory. Path traversal is a vulnerability that allows an attacker to access files or directories that are stored outside the web root folder by manipulating variables such as file paths.
Recommendations Upgrade to Apache MINA SSHD version 2.18.0. Upgrade to Apache MINA SSHD version 3.0.0-M4. Implement additional security controls to govern access to git repositories and allowed operations instead of relying solely on file system layout and permissions.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48827
GHSA-MW4M-QHPG-J82M
OPENSUSE-SU-2026:10919-1
SUSE-SU-2026:2472-1

Affected Products

Apache Mina Sshd