CVE-2026-94052Critical· 9.1▾ MidnightA missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-si…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.
Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.
sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is not affected by this vulnerability, which concerns only LdapPasswordAuthenticator.
Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.
org.apache.sshd:sshd-ldap >= 1.2.0 < 2.20.0org.apache.sshd:sshd-ldap >= 3.0.0-M1 < 3.0.0-M6Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94053Critical· 9.1Apache MINA SSHD: LDAP injection in sshd-ldap
CVE-2026-93994High· 8.1Apache MINA SSHD: Repeated-publickey policy bypass on server
CVE-2026-94002High· 7.5Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
CVE-2026-93996Medium· 6.5Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
CVE-2026-93995Medium· 6.5Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the server
CVE-2026-94029Medium· 6.5Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension