A medium severity vulnerability affecting awscli versions <= 1.45.27, identified as CVE-2026-18654 with a CVSS score of 6.9, exists in the AWS CLI where EMR SSH helper commands passed StrictHostKeyChecking=no to the underlying SSH client, disabling host key verification. This flaw allows a network-positioned actor to perform a man-in-the-middle action and intercept SSH sessions and file transfers between the client and EMR cluster instances. Successful exploitation requires the actor to have network access on the path between the client machine and the EMR cluster endpoint, resulting in full visibility of commands executed, files transferred, and credentials passed over the SSH session.
We recommend you to update AWS CLI to version 1.45.28.[/subscribe_to_unlock_form]
A medium severity vulnerability affecting awscli versions <= 1.45.27, identified as CVE-2026-18654 with a CVSS score of 6.9, exists in the AWS CLI where EMR SSH helper commands passed StrictHostKeyChecking=no to the underlying SSH client, disabling host key verification. This flaw allows a network-positioned actor to perform a man-in-the-middle action and intercept SSH sessions and file transfers between the client and EMR cluster instances. Successful exploitation requires the actor to have network access on the path between the client machine and the EMR cluster endpoint, resulting in full visibility of commands executed, files transferred, and credentials passed over the SSH session.
We recommend you to update AWS CLI to version 1.45.28.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]