{"id":"CVE-2026-93994","title":"Apache MINA SSHD is a Java library for client-side and server-side SSH","summary":"Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by settin…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-304","CWE-303"],"vendor":"Apache Software Foundation","product":"org.apache.sshd:sshd-core","affected":["org.apache.sshd:sshd-core < 2.20.0","org.apache.sshd:sshd-core >= 3.0.0-M1 < 3.0.0-M6"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T16:13:13.493","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93994","references":[{"url":"https://lists.apache.org/thread.html/9t3vsm8rnvwdv9779mlg1lq2fbwojdwp","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/29/33","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93994.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-93994"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2543862"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93994"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93994"},{"url":"https://access.redhat.com/errata/RHSA-2026:71541"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00457,"epssPercentile":0.3727,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-30T14:29:28.530614Z"},"ingestedAt":"2026-09-30T10:01:20.473Z","patched":["hardened_images"],"slug":"CVE-2026-93994","body":"## Overview\n\nApache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods \"publickey,publickey\". Apache MINA SSHD provides an equivalent configuration mechanism.\n\n\n\n\nIn Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass.\n\n\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:71541** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71541)\n- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · no fix planned: Red Hat JBoss Enterprise Application Platform 7, OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, … · updated 2026-10-01 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93994.json)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}