Junglewise Threat Intelligence

CVE-2026-56452: Apache MINA SSHD path traversal in sshd-scp

CVE-2026-56452 · Severity: high · CVSS 7.5 · Published 2026-07-20

Vendors: Apache Software Foundation.

Executive brief

Apache MINA SSHD is a software library used by Java applications to provide secure file transfer (SSH/SCP) capabilities. A vulnerability in the file-receiving component allows a malicious sender to bypass intended folder restrictions. This could result in an attacker overwriting sensitive system files or placing malicious files in unauthorized locations on the server.

Technical details

A path traversal vulnerability exists in the sshd-scp component of Apache MINA SSHD due to insufficient validation of filenames in SCP 'C' (create) and 'D' (directory) commands. When an application is configured to receive files via SCP, a remote attacker can provide filenames containing path traversal sequences (e.g., ../). This allows the attacker to write files to arbitrary locations outside of the intended destination directory on the filesystem. The issue affects versions prior to 2.19.0 and 3.0.0-M5 specifically when the sshd-scp module is utilized.

Affected products

  • Apache Software Foundation MINA SSHD < 2.19.0, 3.0.0-M1 to 3.0.0-M4

Timeline

  • 2026-07-20: advisory: NVD publication date
  • 2026-07-20: disclosed

References