CVE-2026-94053
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.
Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.
sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure it to be used for password of public key authentication.
Other Apache MINA SSHD servers are not affected.
Lack of escaping LDAP filter metacharacters enabled successful authentication with username "*" and password "*".
Leer descripción completaMostrar menos
Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue by properly escaping filter parameters according to RFC 4515.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.55%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 1/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-90, CWE-305
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-94053",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-94053",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-09-30T14:29:56.091889Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@apache.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache MINA SSHD",
"versions": [
{
"status": "affected",
"version": "1.2.0",
"lessThan": "2.20.0",
"versionType": "maven"
},
{
"status": "affected",
"version": "3.0.0-M1",
"lessThan": "3.0.0-M6",
"versionType": "maven"
}
],
"packageURL": "pkg:maven/org.apache.sshd/sshd-ldap",
"packageName": "org.apache.sshd:sshd-ldap",
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-09-30T10:17:18.283",
"references": [
{
"url": "https://lists.apache.org/thread.html/cyrxkdzl3c70rrqs3klqphqz1hwm7p41",
"source": "security@apache.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/29/39",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "security@apache.org",
"description": [
{
"lang": "en",
"value": "CWE-90"
},
{
"lang": "en",
"value": "CWE-305"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.\n\n\n\n\nApache MINA SSHD is a Java library for client-side and server-side SSH. \nThe optional sshd-ldap component provides support for integrating \npassword and publickey authentication on the server side with an LDAP \nserver.\n\n\n\n\nsshd-ldap is an optional component. SSH servers implemented with Apache \nMINA SSHD are affected only if they use sshd-ldap and do configure it to be used for password of public key authentication.\n\nOther Apache MINA SSHD servers are not affected.\n\n\n\n\nLack of escaping LDAP filter metacharacters enabled successful authentication with username \"*\" and password \"*\".\n\n\n\n\nUsers are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue by properly escaping filter parameters according to RFC 4515."
}
],
"lastModified": "2026-09-30T16:13:13.493",
"sourceIdentifier": "security@apache.org"
}