CVE-2026-94052: CWE-304 Missing critical step in authentication in Apache Software Foundation Apache MINA SSHD
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator. Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.
AI Analysis
Technical Summary
Apache MINA SSHD is a Java library for SSH client and server implementations. The optional sshd-ldap component integrates LDAP-based authentication. In affected versions, a missing critical step in the LdapPasswordAuthenticator allows attackers to bypass authentication checks, effectively granting unauthorized access. This vulnerability is tracked as CWE-304 (Missing Authentication for Critical Function). It affects only deployments using sshd-ldap with LdapPasswordAuthenticator for password authentication, not the default sshd-core mechanisms. The issue is fixed in versions 2.20.0 and 3.0.0-M6.
Potential Impact
Successful exploitation allows an attacker to bypass password authentication when using the LdapPasswordAuthenticator in sshd-ldap, potentially granting unauthorized access to the SSH server. The CVSS 3.1 score is 9.1 (Critical), reflecting network attack vector, low complexity, no privileges required, no user interaction, and high confidentiality and integrity impact. Availability is not impacted.
Mitigation Recommendations
Users should upgrade affected Apache MINA SSHD applications to version 2.20.0 or 3.0.0-M6 or later, which include the fix for this vulnerability. No other mitigation or workaround is indicated. If sshd-ldap with LdapPasswordAuthenticator is not used, this vulnerability does not apply.
CVE-2026-94052: CWE-304 Missing critical step in authentication in Apache Software Foundation Apache MINA SSHD
Description
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator. Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.
CVSS v3.1
Score 9.1critical
Affected software
Apache Software Foundation
Apache MINA SSHD
pkg:maven/Apache Software Foundation/org.apache.sshd:sshd-ldapRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache MINA SSHD is a Java library for SSH client and server implementations. The optional sshd-ldap component integrates LDAP-based authentication. In affected versions, a missing critical step in the LdapPasswordAuthenticator allows attackers to bypass authentication checks, effectively granting unauthorized access. This vulnerability is tracked as CWE-304 (Missing Authentication for Critical Function). It affects only deployments using sshd-ldap with LdapPasswordAuthenticator for password authentication, not the default sshd-core mechanisms. The issue is fixed in versions 2.20.0 and 3.0.0-M6.
Potential Impact
Successful exploitation allows an attacker to bypass password authentication when using the LdapPasswordAuthenticator in sshd-ldap, potentially granting unauthorized access to the SSH server. The CVSS 3.1 score is 9.1 (Critical), reflecting network attack vector, low complexity, no privileges required, no user interaction, and high confidentiality and integrity impact. Availability is not impacted.
Mitigation Recommendations
Users should upgrade affected Apache MINA SSHD applications to version 2.20.0 or 3.0.0-M6 or later, which include the fix for this vulnerability. No other mitigation or workaround is indicated. If sshd-ldap with LdapPasswordAuthenticator is not used, this vulnerability does not apply.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-09-19T22:05:42.086Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abcdbaa0df196e1a9d76177
Added to database: 09/30/2026, 09:51:38 UTC
Last enriched: 09/30/2026, 09:57:34 UTC
Last updated: 09/30/2026, 11:12:10 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.