CVE-2026-94052
Received Received - Intake

Authentication Bypass in Apache MINA SSHD via LDAP

Vulnerability report for CVE-2026-94052, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Apache Software Foundation

Description

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is aΒ Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator. Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
apache minas_shh From 1.2.0 (inc) to 2.19.0 (inc)
apache minas_shh From 3.0.0-m1 (inc) to 3.0.0-m5 (inc)
apache minas_shh 2.20.0
apache minas_shh 3.0.0-m6
apache mina From 1.2.0 (inc) to 2.19.0 (inc)
apache mina From 3.0.0-M1 (inc) to 3.0.0-M5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-304 The product implements an authentication technique, but it skips a step that weakens the technique.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

A missing check in LdapPasswordAuthenticator in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 allowed bypassing authentication checks. This vulnerability only affects servers using the sshd-ldap component with an LdapPasswordAuthenticator configured.

Detection Guidance

To detect this vulnerability, check if your Apache MINA SSHD server uses the sshd-ldap component with an LdapPasswordAuthenticator configured. Verify the version of Apache MINA SSHD in use. If it is between 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5, the system is vulnerable.

Impact Analysis

An attacker could exploit this to bypass authentication and gain unauthorized access to the SSH server if it uses the vulnerable LdapPasswordAuthenticator. Normal password authentication via sshd-core is not affected.

Compliance Impact

This vulnerability allows authentication bypass in SSH servers using the sshd-ldap component, potentially granting unauthorized access. This could lead to unauthorized data access or exfiltration, violating confidentiality requirements in GDPR and HIPAA. Non-compliance risks include fines and legal penalties under these regulations.

Mitigation Strategies

Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6 or later to fix the missing authentication check in LdapPasswordAuthenticator.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94052. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart