---
id: CVE-2026-94052
title: 'Apache MINA SSHD: LDAP password authentication ineffective'
summary: "A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.\n\n\n\n\nApache MINA SSHD is a\_Java library for client-side and server-si…"
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cvssSource: cna
cwe:
  - CWE-304
vendor: Apache Software Foundation
product: 'org.apache.sshd:sshd-ldap'
affected:
  - 'org.apache.sshd:sshd-ldap >= 1.2.0 < 2.20.0'
  - 'org.apache.sshd:sshd-ldap >= 3.0.0-M1 < 3.0.0-M6'
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T09:34:43.917Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-94052'
references:
  - url: 'https://lists.apache.org/thread.html/qch5kdwwms13y6bylb7c6qqzq718wn24'
tags:
  - cve.org
ingestedAt: '2026-09-30T10:01:20.475Z'
---

## Overview

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.




Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.




sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator.




Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.

## Affected

- `org.apache.sshd:sshd-ldap >= 1.2.0 < 2.20.0`
- `org.apache.sshd:sshd-ldap >= 3.0.0-M1 < 3.0.0-M6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
