Sceawere
Vulnerability Detail
CVE-2026-77185UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache MINA SSHD Authentication Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 2h ago
- Vendor
- Apache Software Foundation
- Product
- Apache MINA SSHD
- Attack Type
- CWE-305 Authentication Bypass by Primary Weakness
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authentication" exists. A server implemented with Apache MINA SSHD must contain explicit code to make use of this feature. The implementation of this feature was flawed and could potentially lead to skipping checking the signature in public-key or hostbased authentication, or returning a wrong result. Users are recommended to upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error and which additionally forbid the use of this "asynchronous authentication" mechanism with the public-key or hostbased authentication schemes: if used, the SSH session will be closed and the server will log an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-09-30T10:17:17.123Z",
"pubdate": "2026-09-30T10:17:17.123Z",
"executiveSummary": "A critical logic flaw exists in the asynchronous authentication mechanism of Apache MINA SSHD, an open-source Java library used for implementing SSH server and client functionality.\nThe vulnerability allows for an authentication bypass during public-key or host-based authentication phases if a server implementation explicitly utilizes the flawed asynchronous authentication feature.\nBy triggering this logic error, an unauthenticated attacker may successfully bypass security controls, leading to unauthorized access to the SSH session.\nThis vulnerability is restricted to environments where the server application has specifically enabled and implemented the vulnerable asynchronous authentication feature, which the maintainers identify as a rare configuration.\nThe risk implication is significant as it facilitates potential remote code execution or unauthorized system access depending on the context of the SSH server. No specific authentication or privilege is required for the attacker to attempt exploitation, provided the network is exposed to the vulnerable SSH service.\nRemediation requires upgrading to version 2.20.0 or 3.0.0-M6, which strictly enforces a restrictive policy on supported authentication types for the asynchronous mechanism.",
"technicalDetails": "The root cause of the vulnerability resides in the asynchronous authentication implementation within the sshd-core component of Apache MINA SSHD. The framework allows server implementations to defer authentication verification results; however, the internal state management of the authentication flow is flawed when handling specific non-interactive authentication schemes.\nSpecifically, the implementation fails to correctly validate the cryptographic integrity of public-key or host-based authentication signatures when the asynchronous pathway is invoked. Instead of enforcing a mandatory signature verification step, the logic can be coerced into returning an erroneous success signal, effectively bypassing the challenge-response mechanism.\nThe attack flow proceeds as follows: An attacker initiates an SSH handshake with a target server utilizing Apache MINA SSHD. The client requests public-key or host-based authentication. If the server implementation leverages the asynchronous authentication feature, the attacker sends a malformed or improperly sequenced authentication request. Due to the state machine flaw, the sshd-core library may fail to process the underlying signature verification correctly, resulting in an unauthenticated session being treated as successfully authenticated.\nThe vulnerability affects Apache MINA SSHD versions 2.0.0 through 2.19.0, and 3.0.0-M1 through 3.0.0-M5. The component primarily affected is the server-side authentication processing module within sshd-core.\nThe post-exploitation impact allows an attacker to gain an authenticated SSH session without possessing the valid cryptographic material (private keys) required for identity proofing. Because this occurs at the protocol negotiation and authentication layer, the attacker may gain access to the shell or subsystem capabilities provided by the server implementation, potentially leading to full system compromise depending on the user context of the sshd process.\nThe updated versions 2.20.0 and 3.0.0-M6 mitigate this by modifying the authentication workflow logic. The maintainers have implemented a hard constraint where the asynchronous authentication mechanism is strictly prohibited for public-key and host-based authentication. If a server attempts to use asynchronous authentication for these schemes, the session is now explicitly terminated, and a warning is logged to the server logs to alert administrators to invalid configurations."
}