Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94053— Apache MINA SSHD: LDAP injection in sshd-ldap

Quick assessment

Affected
Apache Software Foundation Apache MINA SSHD
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache MINA SSHD 版本 1.2.0 至 2.19.0 以及 3.0.0-M1 至 3.0.0-M5 中的 sshd-ldap 组件存在通过 LDAP 注入导致的身份验证绕过漏洞。 Apache MINA SSHD 是一个用于客户端和服务器端 SSH 的 Java 库。可选的 sshd-ldap 组件支持在服务器端将密码认证和公钥认证与 LDAP 服务器集成。 sshd-ldap 是一个可选组件。仅当使用 Apache MINA SSHD 实现的 SSH 服务器启用了 sshd-ldap,并配置其用于

CVSS 9.1 · Critical

Possible ATT&CK Techniques 1 AI

T1556.002 · Password Filter DLL
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94053

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache MINA SSHD: LDAP injection in sshd-ldap
Source: CVE Program / CVE List V5
Vulnerability Description
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure it to be used for password of public key authentication. Other Apache MINA SSHD servers are not affected. Lack of escaping LDAP filter metacharacters enabled successful authentication with username "*" and password "*". Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue by properly escaping filter parameters according to RFC 4515.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
LDAP查询中使用的特殊元素转义处理不恰当(LDAP注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache MINA SSHD 1.2.0 ~ 2.20.0 -

II. Public POCs for CVE-2026-94053

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94053

请登录查看更多情报信息。

Other References for CVE-2026-94053 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-30 · 19 CVEs total

CVE-2026-102508 9.2 CRITICAL Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, an
CVE-2026-94052 9.1 CRITICAL Apache MINA SSHD: LDAP password authentication ineffective
CVE-2026-77185 9.1 CRITICAL Apache MINA SSHD: Asynchronous authentication can bypass signature verification
CVE-2026-102509 8.7 HIGH Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver an
CVE-2026-102510 8.7 HIGH Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled len
CVE-2026-102511 8.5 HIGH Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed resp
CVE-2026-93994 8.1 HIGH Apache MINA SSHD: Repeated-publickey policy bypass on server
CVE-2026-94002 7.5 HIGH Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
CVE-2026-93995 6.5 MEDIUM Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the ser
CVE-2026-94029 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension
CVE-2026-93996 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
CVE-2026-95616 Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.5
CVE-2026-85532 Apache WSS4J: Insufficient Validation of Derived-Key Parameters
CVE-2026-87830 Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.
CVE-2026-88920 Apache WSS4J: SAML Sender-Vouches Authentication Bypass
CVE-2026-89238 Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti
CVE-2026-92121 Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an ST
CVE-2026-92899 Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce

IV. Related Vulnerabilities

V. Comments for CVE-2026-94053

No comments yet


Leave a comment