CVE-2026-94052: Apache MINA SSHD: LDAP password authentication ineffective
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.
Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.
sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is not affected by this vulnerability, which concerns only LdapPasswordAuthenticator.
Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache MINA SSHD sshd-ldapto a version that resolves this vulnerability.Fixed in 2.20.0 - Upgrade
Upgrade
Apache MINA SSHD sshd-ldapto a version that resolves this vulnerability.Fixed in 3.0.0-M6
Event History
Frequently Asked Questions
Which deployments are affected?
Only server-side SSH deployments that include the optional sshd-ldap component and explicitly configure LdapPasswordAuthenticator for password authentication are affected. Applications using the built-in sshd-core password authentication mechanisms are not affected.
What does an attacker need to exploit this issue?
The affected configuration bypasses authentication checks in LdapPasswordAuthenticator. The supplied vector indicates exploitation is network-accessible, requires no privileges or user interaction, and has low attack complexity.
What should we do if an affected configuration is identified?
Upgrade the affected application to Apache MINA SSHD version 2.20.0 or 3.0.0-M6. If upgrading cannot occur immediately, remove or stop using LdapPasswordAuthenticator for password authentication; built-in sshd-core password authentication is not affected.
How can we determine whether our SSH server is exposed?
Review the application's Apache MINA SSHD version and server authentication configuration. Exposure requires versions 1.2.0 through 2.19.0 or 3.0.0-M1 through 3.0.0-M5, the sshd-ldap component, and a configured LdapPasswordAuthenticator for password authentication.