Sceawere
Vulnerability Detail
CVE-2026-94053UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LDAP Injection Authentication Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 2h ago
- Vendor
- Apache Software Foundation
- Product
- Apache MINA SSHD
- Attack Type
- CWE-90 Improper neutralization of special elements used in an LDAP query ('LDAP injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure it to be used for password of public key authentication. Other Apache MINA SSHD servers are not affected. Lack of escaping LDAP filter metacharacters enabled successful authentication with username "*" and password "*". Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue by properly escaping filter parameters according to RFC 4515.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-09-30T10:17:18.283Z",
"pubdate": "2026-09-30T10:17:18.283Z",
"executiveSummary": "A critical authentication bypass vulnerability exists in the sshd-ldap component of Apache MINA SSHD due to improper neutralization of special characters in LDAP filter queries. This vulnerability allows an unauthenticated remote attacker to gain unauthorized access to an SSH server by injecting malicious input into the authentication parameters.\nThe flaw specifically affects instances where the optional sshd-ldap component is enabled for password or public key authentication. By submitting specific LDAP filter metacharacters, such as an asterisk, an attacker can manipulate the backend LDAP query to return a successful authentication result without providing valid credentials.\nThe risk is severe, as it enables total compromise of the authentication mechanism, potentially granting unauthorized access to the underlying system. This vulnerability stems from a failure to sanitize input before it is incorporated into the search filter, violating fundamental secure coding practices regarding LDAP query construction.\nAffected versions include Apache MINA SSHD 1.2.0 through 2.19.0 and 3.0.0-M1 through 3.0.0-M5. Organizations relying on this library for LDAP-backed authentication should prioritize upgrading to the patched releases to remediate this vector.",
"technicalDetails": "The vulnerability is classified as an LDAP Injection attack located within the sshd-ldap component of the Apache MINA SSHD library. The root cause is the inadequate sanitization of user-supplied credentials before they are processed by the LDAP filtering logic. Specifically, the component fails to properly escape LDAP filter metacharacters as defined by RFC 4515.\nIn a standard implementation, when a user attempts to authenticate via LDAP, the sshd-ldap component constructs an LDAP search filter to verify the user's existence and credentials against the directory service. Because the application logic concatenates the username and password directly into the filter string without secondary encoding or parameterized input handling, an attacker can supply crafted input to terminate the intended search condition and inject arbitrary logic into the filter.\nThe exploitation method leverages the wildcard metacharacter ('*'). By providing '*' as both the username and password, the resulting LDAP filter string is altered. For example, if the application constructs a filter such as '(&(uid=USER)(userPassword=PASS))', the injection of '*' results in '(&(uid=*)(userPassword=*))'. This effectively changes the filter from a credential verification query to a broad existence check. If the LDAP server is configured to return a match for such a wildcard query, the Apache MINA SSHD component interprets the result as a successful authentication, bypassing the intended verification steps.\nThe attack flow proceeds as follows: 1. The attacker initiates an SSH authentication request. 2. The sshd-ldap component prompts for credentials. 3. The attacker inputs malicious metacharacters (e.g., '*') instead of standard credentials. 4. The application logic injects these characters into the LDAP search query without RFC 4515 compliant escaping. 5. The LDAP server executes the malformed query, which evaluates to 'true' based on the wildcard match. 6. The sshd-ldap component receives the successful match signal and permits the session to proceed, granting the attacker access to the server with the privileges associated with the matched user entry.\nThis vulnerability is restricted to environments explicitly using the optional sshd-ldap integration. It is triggered by unauthenticated remote users during the initial authentication phase. Because the exploit occurs at the protocol negotiation level, it does not require prior knowledge of legitimate usernames or passwords, making it highly impactful for exposed SSH endpoints."
}