CVE-2026-77185: Apache MINA SSHD: Asynchronous authentication can bypass signature verification

Published Sep 29, 2026
·
Updated

Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server.

Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authentication" exists. A server implemented with Apache MINA SSHD must contain explicit code to make use of this feature. The implementation of this feature was flawed and could potentially lead to skipping checking the signature in public-key or hostbased authentication, or returning a wrong result.

Users are recommended to upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error and which additionally forbid the use of this "asynchronous authentication" mechanism with the public-key or hostbased authentication schemes: if used, the SSH session will be closed and the server will log an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication.

Affected Software

1 affected component
Apache MINA SSHD>=2.0.0<=2.19.0, >=3.0.0-M1<=3.0.0-M5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache MINA SSHD to a version that resolves this vulnerability.

    Fixed in 2.20.0
  2. Upgrade

    Upgrade Apache MINA SSHD to a version that resolves this vulnerability.

    Fixed in 3.0.0-M6

Event History

Sep 30, 2026
CVE Published
via MITRE·09:47 AM
Data Sourced
via MITRE·09:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected in practice?

Only Apache MINA SSHD server implementations that explicitly use its asynchronous authentication feature are affected. The issue is described as applying to a presumed rare implementation pattern; ordinary use of the library without explicit asynchronous authentication code is not indicated as affected.

2

What authentication methods are at risk?

The flawed logic can skip signature verification or return an incorrect result for public-key or hostbased authentication when asynchronous authentication is used. Password and keyboard-interactive authentication are not identified as having this signature-verification issue.

3

What should teams do if they use asynchronous authentication?

Upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6. These versions fix the logic error and reject asynchronous authentication with public-key or hostbased schemes by closing the SSH session and logging an entry.

4

How can an operator identify potentially affected usage?

Review the SSH server implementation for explicit use of Apache MINA SSHD's asynchronous authentication mechanism, especially alongside public-key or hostbased authentication. After upgrading, attempts to use that combination cause the session to close and generate a log entry stating that asynchronous authentication is permitted only for password or keyboard-interactive authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203