Sceawere
Vulnerability Detail
CVE-2026-93994UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Authentication Bypass in Apache MINA
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 2h ago
- Vendor
- Apache Software Foundation
- Product
- Apache MINA SSHD
- Attack Type
- CWE-304 Missing critical step in authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD provides an equivalent configuration mechanism. In Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-09-30T10:17:17.460Z",
"pubdate": "2026-09-30T10:17:17.460Z",
"executiveSummary": "This vulnerability is an authentication bypass flaw residing within the multi-factor authentication implementation of the Apache MINA SSHD library. It is categorized as a logic error where the server-side validation logic fails to enforce uniqueness among multiple public keys when a multi-authentication scheme is configured.\nThe vulnerability affects both the 2.x and 3.x branches of the sshd-core component. By design, environments requiring dual-factor public key authentication (e.g., 'publickey,publickey') expect distinct cryptographic signatures. However, the flaw allows an attacker possessing a single authorized key pair to present that same key twice to satisfy both authentication requirements.\nThe impact is a significant reduction in the security posture of systems relying on multi-factor authentication, effectively reducing a two-factor requirement to a single-factor requirement. An attacker with access to a single valid private key can bypass the intended policy, potentially gaining unauthorized access to the SSH server. This risk is critical for environments mandating strong identity verification. The flaw is exploitable over the network by any user possessing at least one valid credential authorized by the server's policy.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient state validation within the authentication handshake process of the sshd-core component. When Apache MINA SSHD is configured to require multi-factor public key authentication—modeled after OpenSSH's AuthenticationMethods 'publickey,publickey' directive—the server is expected to maintain an internal record of successfully authenticated public keys throughout the session authentication sequence.\nThe vulnerable code fails to implement a verification check to ensure that the public key provided in the second authentication step is cryptographically distinct from the public key used in the first step. Consequently, the server-side authentication state machine treats each authentication request independently without verifying the uniqueness of the key identifier or the public key material.\nThe attack flow proceeds as follows: 1) The attacker initiates an SSH connection to a server configured for dual public key authentication. 2) The server requests the first authentication factor. 3) The attacker presents a valid, authorized public key/signature. 4) The server validates the signature, records success, and requests the second factor. 5) Instead of presenting a second, unique key, the attacker replays the exact same public key and signature or re-authenticates with the same valid credential. 6) Because the server lacks logic to compare the current authentication attempt against the previous successful one, it validates the duplicate key and grants full access to the session.\nThis behavior constitutes a partial authentication bypass, as it successfully circumvents the security policy intended to force the combination of two distinct cryptographic identities. The vulnerability exists in all Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 through 3.0.0-M5. The component affected is limited to sshd-core, which handles the session management and protocol-level exchanges for the SSH library. Exploitation is remote and requires no additional privileges beyond possessing one authorized public key that is recognized by the target server."
}