Sceawere

Vulnerability Detail

CVE-2026-93995UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache MINA SSHD Git Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
Apache Software Foundation
Product
Apache MINA SSHD
Attack Type
CWE-20 Improper Input Validation
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that authenticated SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. In CVE-2026-58624 this mechanism was restricted to only a few git commands, including "git archive" without "--output" or "-o" options such that the resulting archive would not be written on the server but instead sent back to the client over the SSH connection. The fix done for CVE-2026-58624 was insufficient as it missed removing the single-argument "-o=file.zip" version of the command parameter from the "archive" command. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T10:17:17.597Z",
  "pubdate": "2026-09-30T10:17:17.597Z",
  "executiveSummary": "This vulnerability involves improper input validation within the org.apache.sshd:sshd-git component of Apache MINA SSHD. It represents a security regression following an incomplete fix for CVE-2026-58624. The flaw allows authenticated SSH clients to execute unauthorized file operations on the server hosting Git repositories.\nThe vulnerability type is an Improper Input Validation flaw, specifically involving argument injection in the GitPgmCommandFactory. Successful exploitation allows an authenticated attacker to bypass restricted command execution parameters, potentially resulting in unauthorized file creation or overwriting on the host filesystem via the 'git archive' command.\nAffected products include Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 through 3.0.0-M5. The risk is significant as it provides a mechanism for remote attackers to interact with the underlying filesystem in ways that were explicitly intended to be prohibited. Exploitation requires the attacker to possess valid SSH credentials to interact with the GitPgmCommandFactory, and the impact is dependent on the permissions of the user running the SSH server process.",
  "technicalDetails": "The root cause of this vulnerability lies in an insufficient sanitization mechanism within the GitPgmCommandFactory class, which manages the execution of Git commands via the JGit library. The system was designed to restrict 'git archive' command execution to prevent arbitrary file writes by explicitly blacklisting the '--output' and '-o' command-line options. However, the implementation failed to account for the single-argument syntax '-o=file.zip'.\nIn the previous remediation efforts for CVE-2026-58624, the filter logic failed to validate the concatenated format of the output flag. Because the input parser does not correctly normalize or evaluate the '=' character in the context of the output argument, the command line parser interprets '-o=file.zip' as a valid instruction to write the archive to a specific path on the server filesystem. This allows an attacker to bypass the security control intended to force the 'git archive' output to be streamed solely over the SSH connection.\nThe attack flow proceeds as follows: First, the attacker establishes an authenticated SSH session with the target server configured with GitPgmCommandFactory. Second, the attacker invokes the 'git archive' command, passing the prohibited argument format '-o=filename'. Because the server-side validator ignores the specific variant of the '-o' flag, the command is passed to the underlying JGit execution layer. Finally, the JGit library executes the archive operation, resulting in the creation or modification of a file at the location specified by the attacker within the server's filesystem.\nThe component affected is org.apache.sshd:sshd-git. This vulnerability is restricted to authenticated users, meaning an attacker must have valid credentials to reach the Git command factory. The network exposure is limited to servers where the sshd-git module is explicitly enabled and configured for remote Git repository access. Post-exploitation impact may include the ability to overwrite system files, manipulate configuration files, or perform data exfiltration if the SSH service process runs with elevated privileges on the host system."
}
CVE-2026-93995: Apache MINA SSHD Git Injection (MEDIUM Severity, CVSS: 6.5) | Sceawere