Authentication Bypass Vulnerability in Apache MINA SSHD Library
CVE-2026-77185
What is CVE-2026-77185?
The Apache MINA SSHD library contains a flaw that enables an authentication bypass in versions 2.0.0 to 2.19.0, and 3.0.0-M1 to 3.0.0-M5. This issue arises from a misimplementation of the asynchronous authentication feature, allowing an SSH server using this library to skip signature checks during public-key or hostbased authentication. Such a lapse can result in unauthorized access. Users are strongly advised to update to version 2.20.0 or 3.0.0-M6, which patches this vulnerability by tightening the authentication logic and ensuring the asynchronous method is exclusively utilized with password or keyboard-interactive authentication.
Affected Version(s)
Apache MINA SSHD 2.0.0 < 2.20.0
Apache MINA SSHD 3.0.0-M1 < 3.0.0-M6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved