The notice, published on September 29, 2026 and presented as an automatic translation of a post on the oss-sec feed, describes CVE-2026-94052 in Apache MINA SSHD’s sshd-ldap component, a Java library for SSH. According to the text, a missing check in LdapPasswordAuthenticator allowed LDAP password authentication checks to be bypassed.
Affected versions are 1.2.0 before 2.20.0 and 3.0.0-M1 before 3.0.0-M6. The notice rates the issue critical and gives it a CVSS 3.1 score of 9.1, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. The stated fixed versions are 2.20.0 and 3.0.0-M6.
If your organization uses the library, identify the version in each application and compare it with the affected ranges. Plan an upgrade to a fixed version, validate it in a test environment, and review authentication logs after deployment. Do not assume that an LDAP configuration removes the flaw.
To confirm the notice and check for updates, consult the original post in the oss-sec feed archive and the Apache MINA SSHD project’s security and release notes. Because the supplied text is an automatic translation and is truncated, check the original records before making incident-response decisions.
If you use AI to summarize logs, analyze configurations, or study the notice, do not submit passwords, keys, personal data, or internal details without authorization. Prefer sanitized excerpts and follow your organization’s security rules.