Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-77185— Apache MINA SSHD: Asynchronous authentication can bypass signature verification

Quick assessment

Affected
Apache Software Foundation Apache MINA SSHD
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache MINA SSHD 2.0.0 至 2.19.0 以及 3.0.0-M1 至 3.0.0-M5 版本中,sshd-core 组件存在身份验证绕过漏洞。该漏洞影响以特定(推测较为罕见)方式实现 SSH 服务器的场景。 Apache MINA SSHD 是一个用于客户端和服务器端 SSH 的 Java 库。在该库的服务器部分,存在一种执行“异步身份验证”的机制。使用 Apache MINA SSHD 实现的服务器必须包含显式代码才能利用此功能。然而,该功能的实现存在缺陷,可能导致在公钥认证或基于主机的认证

CVSS 9.1 · Critical

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77185

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache MINA SSHD: Asynchronous authentication can bypass signature verification
Source: CVE Program / CVE List V5
Vulnerability Description
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authentication" exists. A server implemented with Apache MINA SSHD must contain explicit code to make use of this feature. The implementation of this feature was flawed and could potentially lead to skipping checking the signature in public-key or hostbased authentication, or returning a wrong result. Users are recommended to upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error and which additionally forbid the use of this "asynchronous authentication" mechanism with the public-key or hostbased authentication schemes: if used, the SSH session will be closed and the server will log an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用基本弱点进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache MINA SSHD 2.0.0 ~ 2.20.0 -

II. Public POCs for CVE-2026-77185

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77185

请登录查看更多情报信息。

Other References for CVE-2026-77185 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-30 · 19 CVEs total

CVE-2026-102508 9.2 CRITICAL Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, an
CVE-2026-94052 9.1 CRITICAL Apache MINA SSHD: LDAP password authentication ineffective
CVE-2026-94053 9.1 CRITICAL Apache MINA SSHD: LDAP injection in sshd-ldap
CVE-2026-102509 8.7 HIGH Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver an
CVE-2026-102510 8.7 HIGH Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled len
CVE-2026-102511 8.5 HIGH Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed resp
CVE-2026-93994 8.1 HIGH Apache MINA SSHD: Repeated-publickey policy bypass on server
CVE-2026-94002 7.5 HIGH Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
CVE-2026-93995 6.5 MEDIUM Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the ser
CVE-2026-94029 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension
CVE-2026-93996 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
CVE-2026-95616 Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.5
CVE-2026-85532 Apache WSS4J: Insufficient Validation of Derived-Key Parameters
CVE-2026-87830 Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.
CVE-2026-88920 Apache WSS4J: SAML Sender-Vouches Authentication Bypass
CVE-2026-89238 Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti
CVE-2026-92121 Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an ST
CVE-2026-92899 Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce

IV. Related Vulnerabilities

V. Comments for CVE-2026-77185

No comments yet


Leave a comment