CVE-2026-48827
Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory.
Applications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected.
Users are advised to upgrade affected applications to Apche MINA SSHD 2.18.0, which fixes the issue.
The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M3 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git. Upgrade affected applications to 3.0.0-M4.
Leer descripción completaMostrar menos
We would like to point out that a professional git server should not rely solely on file system layout and permissions, but should implement additional security controls to govern access to git repositories and operations allowed on particular git repositories.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.78%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1005Data from Local Systemcollection90 % - Impacto secundario
T1565Data Manipulationimpact70 %
AV:N/PR:L sin UI permite explotar servicios remotos SSH con credenciales. Path traversal (CWE-22) permite lectura/modificación de ficheros git fuera del directorio raíz configurado.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-48827",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-48827",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-01T12:44:52.544626Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@apache.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache MINA SSHD",
"versions": [
{
"status": "affected",
"version": "2.0.0",
"versionType": "maven",
"lessThanOrEqual": "2.17.1"
},
{
"status": "affected",
"version": "3.0.0-M1",
"versionType": "maven",
"lessThanOrEqual": "3.0.0-M3"
}
],
"packageName": "org.apache.sshd:sshd-git",
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-01T09:16:20.307",
"references": [
{
"url": "https://lists.apache.org/thread/910kq9ghm6js0k1yhhbrdm9sf5tqq9c9",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"source": "security@apache.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/05/30/1",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@apache.org",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory.\n\n\n\n\nApplications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected.\n\n\n\n\nUsers are advised to upgrade affected applications to Apche MINA SSHD 2.18.0, which fixes the issue.\n\n\n\n\nThe issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M3 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git. Upgrade affected applications to 3.0.0-M4.\n\n\n\n\nWe would like to point out that a professional git server should not rely solely on file system layout and permissions, but should implement additional security controls to govern access to git repositories and operations allowed on particular git repositories."
},
{
"lang": "es",
"value": "Vulnerabilidad de salto de ruta en el paquete Apache MINA SSHD sshd-git. La falta de validación de ruta en git-upload-pack, git-receive-pack y otras operaciones de git permite a los usuarios autenticados por SSH acceder a repositorios git fuera del directorio raíz del servidor git configurado.\n\nLas aplicaciones se ven afectadas si utilizan org.apache.sshd:sshd-git. Las aplicaciones que no utilizan sshd-git no se ven afectadas.\n\nSe aconseja a los usuarios actualizar las aplicaciones afectadas a Apache MINA SSHD 2.18.0, que soluciona el problema.\n\nEl problema también está presente en los hitos de prelanzamiento 3.0.0-M1 a 3.0.0-M3 para una nueva versión principal próxima 3.0.0. De nuevo, las aplicaciones se ven afectadas solo si utilizan sshd-git. Actualice las aplicaciones afectadas a 3.0.0-M4.\n\nNos gustaría señalar que un servidor git profesional no debe depender únicamente del diseño y los permisos del sistema de archivos, sino que debe implementar controles de seguridad adicionales para gobernar el acceso a los repositorios git y las operaciones permitidas en repositorios git particulares."
}
],
"lastModified": "2026-07-22T07:10:00.107",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:mina_sshd:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5EB0B4D-9C31-4A5F-A476-B57D6C805FFB",
"versionEndExcluding": "2.18.0",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:apache:mina_sshd:3.0.0:m1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32435A6F-3BD6-4AAB-93B1-0B1514419A50"
},
{
"criteria": "cpe:2.3:a:apache:mina_sshd:3.0.0:m2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E399FD6-9A33-4F78-AFCE-F46C7BBC56F1"
},
{
"criteria": "cpe:2.3:a:apache:mina_sshd:3.0.0:m3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13419EBE-E6B4-4895-BF6C-FC910076CC7A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@apache.org"
}