CVE-2026-77185: CWE-305 Authentication Bypass by Primary Weakness in Apache Software Foundation Apache MINA SSHD
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authentication" exists. A server implemented with Apache MINA SSHD must contain explicit code to make use of this feature. The implementation of this feature was flawed and could potentially lead to skipping checking the signature in public-key or hostbased authentication, or returning a wrong result. Users are recommended to upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error and which additionally forbid the use of this "asynchronous authentication" mechanism with the public-key or hostbased authentication schemes: if used, the SSH session will be closed and the server will log an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication.
AI Analysis
Technical Summary
Apache MINA SSHD, a Java library for SSH client and server implementations, contains an authentication bypass vulnerability (CWE-305) in its sshd-core component. The flaw arises from a logic error in the asynchronous authentication feature, which is only used if explicitly implemented by the server. This error can cause the server to skip signature checks during public-key or hostbased authentication or return incorrect results, effectively bypassing authentication. The vulnerability affects versions >=2.0.0 <2.20.0 and >=3.0.0-M1 <3.0.0-M6. The Apache Software Foundation fixed this issue in versions 2.20.0 and 3.0.0-M6 by correcting the logic and disallowing asynchronous authentication with public-key or hostbased schemes, closing the session and logging an event if such usage is attempted.
Potential Impact
Successful exploitation of this vulnerability allows an attacker to bypass authentication on an SSH server implemented with Apache MINA SSHD using asynchronous authentication with public-key or hostbased methods. This results in unauthorized access with full confidentiality and integrity impact, as indicated by the CVSS score of 9.1 (critical). There is no known exploitation in the wild at this time.
Mitigation Recommendations
Users should upgrade affected Apache MINA SSHD versions to 2.20.0 or 3.0.0-M6 or later, where the vulnerability is fixed. These versions correct the authentication logic and prevent asynchronous authentication from being used with public-key or hostbased authentication schemes. If upgrading is not immediately possible, avoid using asynchronous authentication with public-key or hostbased methods. The vendor advisory indicates these fixes are official and complete.
CVE-2026-77185: CWE-305 Authentication Bypass by Primary Weakness in Apache Software Foundation Apache MINA SSHD
Description
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authentication" exists. A server implemented with Apache MINA SSHD must contain explicit code to make use of this feature. The implementation of this feature was flawed and could potentially lead to skipping checking the signature in public-key or hostbased authentication, or returning a wrong result. Users are recommended to upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error and which additionally forbid the use of this "asynchronous authentication" mechanism with the public-key or hostbased authentication schemes: if used, the SSH session will be closed and the server will log an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication.
CVSS v3.1
Score 9.1critical
Affected software
Apache Software Foundation
Apache MINA SSHD
pkg:maven/Apache Software Foundation/org.apache.sshd:sshd-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache MINA SSHD, a Java library for SSH client and server implementations, contains an authentication bypass vulnerability (CWE-305) in its sshd-core component. The flaw arises from a logic error in the asynchronous authentication feature, which is only used if explicitly implemented by the server. This error can cause the server to skip signature checks during public-key or hostbased authentication or return incorrect results, effectively bypassing authentication. The vulnerability affects versions >=2.0.0 <2.20.0 and >=3.0.0-M1 <3.0.0-M6. The Apache Software Foundation fixed this issue in versions 2.20.0 and 3.0.0-M6 by correcting the logic and disallowing asynchronous authentication with public-key or hostbased schemes, closing the session and logging an event if such usage is attempted.
Potential Impact
Successful exploitation of this vulnerability allows an attacker to bypass authentication on an SSH server implemented with Apache MINA SSHD using asynchronous authentication with public-key or hostbased methods. This results in unauthorized access with full confidentiality and integrity impact, as indicated by the CVSS score of 9.1 (critical). There is no known exploitation in the wild at this time.
Mitigation Recommendations
Users should upgrade affected Apache MINA SSHD versions to 2.20.0 or 3.0.0-M6 or later, where the vulnerability is fixed. These versions correct the authentication logic and prevent asynchronous authentication from being used with public-key or hostbased authentication schemes. If upgrading is not immediately possible, avoid using asynchronous authentication with public-key or hostbased methods. The vendor advisory indicates these fixes are official and complete.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-20T16:22:07.843Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abce0dc0df196e1a9de7072
Added to database: 09/30/2026, 10:13:48 UTC
Last enriched: 09/30/2026, 10:27:22 UTC
Last updated: 09/30/2026, 13:21:52 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.