CVE-2026-94053
Received Received - Intake

LDAP Injection Authentication Bypass in Apache MINA SSHD

Vulnerability report for CVE-2026-94053, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Apache Software Foundation

Description

Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure it to be used for password of public key authentication. Other Apache MINA SSHD servers are not affected. Lack of escaping LDAP filter metacharacters enabled successful authentication with username "*" and password "*". Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue by properly escaping filter parameters according to RFC 4515.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache mina From 1.2.0 (inc) to 2.19.0 (inc)
apache mina From 3.0.0-M1 (inc) to 3.0.0-M5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-90 The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
CWE-305 The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in Apache MINA SSHD's sshd-ldap component. It allows attackers to bypass authentication by injecting LDAP filter metacharacters. Specifically, using a username and password of '*' grants unauthorized access.

Detection Guidance

Check if your Apache MINA SSHD server uses the sshd-ldap component for authentication. Verify the version of Apache MINA SSHD in use. If using versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5, the system is vulnerable. Test authentication with username and password set to "*" to see if access is granted.

Impact Analysis

If you use Apache MINA SSHD with the sshd-ldap component configured for authentication, attackers could gain unauthorized access to your SSH server. This could lead to data breaches, unauthorized system control, or further network compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to systems using affected Apache MINA SSHD versions with sshd-ldap enabled. For GDPR, it may result in unauthorized data access or processing, violating principles of lawfulness and security. For HIPAA, it could compromise protected health information integrity or confidentiality if exploited in healthcare systems.

Mitigation Strategies

Upgrade affected Apache MINA SSHD applications to version 2.20.0 or 3.0.0-M6 or later to fix the LDAP injection vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94053. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart