Skip to content
Rota Nacional

Cyber ·

Critical LDAP authentication flaw in Apache MINA SSHD

A notice published on September 29, 2026 reports a critical LDAP password authentication flaw in Apache MINA SSHD. It affects versions before the stated fixes; the source assigns a CVSS 3.1 score of 9.1.

The notice, published on September 29, 2026 and presented as an automatic translation of a post on the oss-sec feed, describes CVE-2026-94052 in Apache MINA SSHD’s sshd-ldap component, a Java library for SSH. According to the text, a missing check in LdapPasswordAuthenticator allowed LDAP password authentication checks to be bypassed.

Affected versions are 1.2.0 before 2.20.0 and 3.0.0-M1 before 3.0.0-M6. The notice rates the issue critical and gives it a CVSS 3.1 score of 9.1, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. The stated fixed versions are 2.20.0 and 3.0.0-M6.

If your organization uses the library, identify the version in each application and compare it with the affected ranges. Plan an upgrade to a fixed version, validate it in a test environment, and review authentication logs after deployment. Do not assume that an LDAP configuration removes the flaw.

To confirm the notice and check for updates, consult the original post in the oss-sec feed archive and the Apache MINA SSHD project’s security and release notes. Because the supplied text is an automatic translation and is truncated, check the original records before making incident-response decisions.

If you use AI to summarize logs, analyze configurations, or study the notice, do not submit passwords, keys, personal data, or internal details without authorization. Prefer sanitized excerpts and follow your organization’s security rules.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free