LOWVulnerability

CVE-2026-86231

A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.

Properties

severity
LOW
score
3.7
cve_id
CVE-2026-86231
signal_observed_at
2026-09-16T21:37:07+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
published_at
2026-09-06T23:17:39.157
last_modified
2026-09-11T21:17:38.907

Related Entities (3)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]
[Weakness]Improper Check for Certificate Revocation

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86231 — Ninja Signal Threat Intelligence | Ninja Signal