CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands
Bulletin ID: 2026-071-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/03/2026 12:30 PM PDT
Description:
AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. We identified CVE-2026-18654, an issue where the EMR SSH helper commands (aws emr ssh, aws emr socks, aws emr put, aws emr get) disabled SSH host key verification, which might allow man-in-the-middle actors to intercept SSH sessions and file transfers via network positioning between the client and the EMR cluster endpoint.
Impacted versions:
- AWS CLI v1 <= 1.45.27
- AWS CLI v2 <= 2.35.2
Resolution:
This issue has been addressed in AWS CLI v1 version 1.45.28 and AWS CLI v2 version 2.35.3. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
There is no workaround. The insecure SSH option was hardcoded and could not be overridden by the user. Customers must upgrade to the fixed versions.
References:
Acknowledgement:
We would like to thank Ali Sunbul for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.