CVE-2026-18654: AWS CLI EMR SSH Host Key Bypass
🟠 High | Source: AWS Security Bulletins A vulnerability in the AWS CLI (CVE-2026-18654) causes EMR SSH helper commands to disable SSH host key verification, leaving sessions and file transfers open to man-in-the-middle interception. This affects all AWS CLI v1 versions up to and including 1.45.27, and all v2 versions up to and including 2.35.2. Anyone using the ‘aws emr ssh’, ‘socks’, ‘put’, or ‘get’ commands on an unpatched CLI could have their traffic intercepted by an attacker with network positioning between the client and the EMR cluster. ...