CVE-2026-94052: Apache MINA SSHD: LDAP password authentication ineffective

Published Sep 29, 2026
·
Updated

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.

Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.

sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is not affected by this vulnerability, which concerns only LdapPasswordAuthenticator.

Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.

Affected Software

1 affected component
Apache Apache MINA SSHD>=1.2.0<=2.19.0, >=3.0.0-M1<=3.0.0-M5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache MINA SSHD sshd-ldap to a version that resolves this vulnerability.

    Fixed in 2.20.0
  2. Upgrade

    Upgrade Apache MINA SSHD sshd-ldap to a version that resolves this vulnerability.

    Fixed in 3.0.0-M6

Event History

Sep 30, 2026
CVE Published
via MITRE·09:34 AM
Data Sourced
via MITRE·09:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Only server-side SSH deployments that include the optional sshd-ldap component and explicitly configure LdapPasswordAuthenticator for password authentication are affected. Applications using the built-in sshd-core password authentication mechanisms are not affected.

2

What does an attacker need to exploit this issue?

The affected configuration bypasses authentication checks in LdapPasswordAuthenticator. The supplied vector indicates exploitation is network-accessible, requires no privileges or user interaction, and has low attack complexity.

3

What should we do if an affected configuration is identified?

Upgrade the affected application to Apache MINA SSHD version 2.20.0 or 3.0.0-M6. If upgrading cannot occur immediately, remove or stop using LdapPasswordAuthenticator for password authentication; built-in sshd-core password authentication is not affected.

4

How can we determine whether our SSH server is exposed?

Review the application's Apache MINA SSHD version and server authentication configuration. Exposure requires versions 1.2.0 through 2.19.0 or 3.0.0-M1 through 3.0.0-M5, the sshd-ldap component, and a configured LdapPasswordAuthenticator for password authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203