A notice published on September 29, 2026 describes a critical LDAP injection flaw that may bypass authentication in Apache MINA SSHD’s sshd-ldap component.
The notice, attributed to Thomas Wolf and published on September 29, 2026 in the oss-sec feed, reports CVE-2026-94053: LDAP injection in the optional sshd-ldap component may allow authentication bypass. Apache MINA SSHD is a Java library for SSH on both client and server sides. The reported severity is critical, with CVSS 3.1 score 9.1; the published vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.
Affected versions are 1.2.0 up to, but not including, 2.20.0, and 3.0.0-M1 up to, but not including, 3.0.0-M6. To assess exposure, consult the original notice in the oss-sec feed and confirm the version ranges and any fixes in official Apache MINA SSHD announcements and CVE records. The supplied text is an automatic translation and ends mid-description; check the original sources before taking action.