---
id: CVE-2026-93994
title: Apache MINA SSHD is a Java library for client-side and server-side SSH
summary: >-
  Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH
  servers can be configured to require multi-authentication schemes, for
  instance two different public keys, not just one. In OpenSSH, this would be
  done by settin…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-304
  - CWE-303
vendor: Apache Software Foundation
product: 'org.apache.sshd:sshd-core'
affected:
  - 'org.apache.sshd:sshd-core < 2.20.0'
  - 'org.apache.sshd:sshd-core >= 3.0.0-M1 < 3.0.0-M6'
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:13:13.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93994'
references:
  - url: 'https://lists.apache.org/thread.html/9t3vsm8rnvwdv9779mlg1lq2fbwojdwp'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/29/33'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93994.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-93994'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2543862'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-93994'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93994'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71541'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00457
epssPercentile: 0.3727
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-30T14:29:28.530614Z'
ingestedAt: '2026-09-30T10:01:20.473Z'
patched:
  - hardened_images
---

## Overview

Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD provides an equivalent configuration mechanism.




In Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass.






Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:71541** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71541)
- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · no fix planned: Red Hat JBoss Enterprise Application Platform 7, OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, … · updated 2026-10-01 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93994.json)
