Sceawere

Vulnerability Detail

CVE-2026-94052UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Authentication Bypass in sshd-ldap

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
2h ago
Vendor
Apache Software Foundation
Product
Apache MINA SSHD
Attack Type
CWE-304 Missing critical step in authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator. Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-09-30T10:17:18.147Z",
  "pubdate": "2026-09-30T10:17:18.147Z",
  "executiveSummary": "A critical authentication bypass vulnerability exists within the LdapPasswordAuthenticator component of Apache MINA SSHD. This security flaw originates from a missing validation check during the authentication process, allowing unauthorized actors to circumvent password verification requirements when integrating with an LDAP backend.\nThe vulnerability specifically impacts implementations utilizing the optional sshd-ldap module. If configured, an attacker can potentially authenticate against an SSH server without providing valid credentials. This poses a severe risk to confidentiality, integrity, and availability, as unauthorized users may gain interactive shell access or execute arbitrary commands depending on the server configuration.\nExploitation is limited to environments where LdapPasswordAuthenticator is explicitly enabled; however, it does not require prior authentication or specialized system access. The attack surface is restricted to the network-exposed SSH service. To mitigate this risk, users must upgrade to the patched versions provided by the vendor, as no secondary configuration workarounds effectively neutralize the logic flaw within the component's codebase.",
  "technicalDetails": "The vulnerability resides within the LdapPasswordAuthenticator class in the sshd-ldap component of the Apache MINA SSHD library. The root cause is a failure to properly implement or execute the authentication logic, resulting in a condition where the authenticator incorrectly signals a successful authentication state regardless of the validity of the provided credentials.\nIn a typical authentication flow, the LdapPasswordAuthenticator is responsible for binding to an LDAP server or performing an attribute search to verify the user's password. Due to the missing check, the logic execution path that should return a failure status when the LDAP backend rejects credentials is circumvented. Instead, the method proceeds as if the authentication attempt was successful, returning a positive result to the SSH server's authentication manager.\nThe attack flow follows these steps: 1) The attacker initiates an SSH connection attempt using password authentication. 2) The server routes the credentials to the configured LdapPasswordAuthenticator. 3) The vulnerability allows the authentication handler to return an 'authenticated' status without successfully validating the credentials against the LDAP server. 4) The SSH server grants the attacker access to the requested session. Because this occurs at the authentication layer, the attacker may be granted the full privileges associated with the target username without ever presenting a valid password.\nAffected versions include 1.2.0 through 2.19.0 and 3.0.0-M1 through 3.0.0-M5. The vulnerability is specific to the sshd-ldap component; standard SSH authentication mechanisms within sshd-core remain unaffected. Successful exploitation requires that the SSH server be configured specifically to use the LdapPasswordAuthenticator for incoming password authentication requests.\nThe post-exploitation impact is significant, as it grants unauthorized users network-level access to the host. Depending on the target environment, this can facilitate lateral movement within the network, unauthorized data exfiltration, or the deployment of persistent malicious payloads. Given the nature of SSH, the lack of authentication check effectively removes the primary gatekeeper for the remote system."
}
CVE-2026-94052: Authentication Bypass in sshd-ldap (CRITICAL Severity, CVSS: 9.1) | Sceawere