{"id":"CVE-2026-94052","title":"Apache MINA SSHD: LDAP password authentication ineffective","summary":"A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.\n\n\n\n\nApache MINA SSHD is a Java library for client-side and server-si…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cvssSource":"cna","cwe":["CWE-304"],"vendor":"Apache Software Foundation","product":"org.apache.sshd:sshd-ldap","affected":["org.apache.sshd:sshd-ldap >= 1.2.0 < 2.20.0","org.apache.sshd:sshd-ldap >= 3.0.0-M1 < 3.0.0-M6"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T09:34:43.917Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-94052","references":[{"url":"https://lists.apache.org/thread.html/qch5kdwwms13y6bylb7c6qqzq718wn24"}],"tags":["cve.org"],"ingestedAt":"2026-09-30T10:01:20.475Z","slug":"CVE-2026-94052","body":"## Overview\n\nA missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.\n\n\n\n\nApache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.\n\n\n\n\nsshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator.\n\n\n\n\nUsers are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.\n\n## Affected\n\n- `org.apache.sshd:sshd-ldap >= 1.2.0 < 2.20.0`\n- `org.apache.sshd:sshd-ldap >= 3.0.0-M1 < 3.0.0-M6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}