CVE-2026-93994

Summary

Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD provides an equivalent configuration mechanism.

In Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass.

Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache MINA SSHD0 < 2.20.0affected
Apache Software FoundationApache MINA SSHD3.0.0-M1 < 3.0.0-M6affected

Weaknesses

  • CWE-304: CWE-304 Missing critical step in authentication

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References