Skip to main content
QUIETLYTIC
Vulnerability

JSch Certificate Revocation Bypass (CVE-2026-86231)

CVE-2026-86231 is a high-complexity improper certificate-revocation-check flaw in the mwiede/jsch Java SSH library, fixed in version 2.28.6.

CVE-2026-86231
Threat Level
LOW
CVSS
3.7
Status
Monitored
Confidence
High
Affected Products
JSch (jsch, mwiede fork)

CVE-2026-86231 affects JSch, a Java library implementing the SSH2 protocol used to embed SSH client functionality directly into Java applications — this record specifically concerns the actively maintained mwiede/jsch fork, which took over development after the original project’s maintenance slowed.

What the vulnerability does

Per the vulnerability record, the flaw is in the getRevokedKeys function of KnownHosts.java. Manipulating the known_hosts argument results in an improper check for certificate (key) revocation — meaning JSch’s mechanism for recognizing a host key that should be treated as revoked can be bypassed under certain conditions. Affected versions run through 2.28.5.

The record explicitly flags this as high attack complexity and states the exploitability is “difficult” — this isn’t a trivially weaponizable bug. CVSS base score is 3.7 (low), consistent with a bypass that requires specific conditions to be met rather than a straightforward remote trigger.

Fix and affected versions

Fixed in JSch 2.28.6, per the project’s own patch (commit 194a2f76a5c0f1c3f778565be3fd66bcafc42d23). Applications embedding JSch for SSH connectivity should upgrade to 2.28.6 or later.

Confidence

This traces to the JSch project’s own repository, with a named function, file, and patch commit — confidence is high.

Why this matters

Certificate/key revocation checks exist specifically to prevent an application from trusting a host key that’s known to be compromised. A bypass in that mechanism weakens (without fully eliminating, given the stated high complexity) the guarantee that a JSch-based SSH client will correctly reject a revoked host key from known_hosts. Applications with a security posture that depends on host-key revocation enforcement — rather than treating known_hosts as an informal convenience — should prioritize the 2.28.6 upgrade even though this isn’t a low-complexity, easily automated exploit.

Frequently Asked Questions

What is CVE-2026-86231? A high-complexity, low-severity (CVSS 3.7) improper certificate-revocation-check vulnerability in the mwiede/jsch Java SSH library, affecting versions through 2.28.5.

Which version fixes CVE-2026-86231? JSch 2.28.6 and later.

Is CVE-2026-86231 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog, and the project’s own record describes exploitation as difficult.


Data sourced from the mwiede/jsch project’s own GitHub repository, aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 mwiede/jsch (GitHub)

Related intelligence


Analyst tools