OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-94052

CRITICAL · CVSS 9.1 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The LdapPasswordAuthenticator component in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 is vulnerable due to a missing authentication check, allowing unauthorized access to systems using this LDAP integration for password authentication. This critical vulnerability (CVSS 9.1) primarily impacts organizations utilizing the sshd-ldap component for SSH server implementations. Users should prioritize upgrading to version 2.20.0 or 3.0.0-M6 to mitigate this risk.

CVE
CVE-2026-94052
Severity
CRITICAL
CVSS
9.1
EPSS
0.38%
Apache Java

Original NVD Description

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator. Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.