Apache · Apache Mina Sshd · CVE-2026-94053
**Name of the Vulnerable Software and Affected Versions**
Apache MINA SSHD versions 1.2.0 through 2.19.0
Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5
**Description**
An authentication bypass exists in the optional `sshd-ldap` component, which integrates password and public key authentication with an LDAP server. The issue stems from a lack of escaping for LDAP filter metacharacters, allowing successful authentication by using `*` for both the `username` and `password` variables.
**Recommendations**
Update Apache MINA SSHD versions 1.2.0 through 2.19.0 to version 2.20.0.
Update Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5 to version 3.0.0-M6.
Restrict the use of the `sshd-ldap` component if it is not required for authentication.