Authentication Bypass Vulnerability in Apache MINA SSHD Library
CVE-2026-77185

9.1CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-77185?

The Apache MINA SSHD library contains a flaw that enables an authentication bypass in versions 2.0.0 to 2.19.0, and 3.0.0-M1 to 3.0.0-M5. This issue arises from a misimplementation of the asynchronous authentication feature, allowing an SSH server using this library to skip signature checks during public-key or hostbased authentication. Such a lapse can result in unauthorized access. Users are strongly advised to update to version 2.20.0 or 3.0.0-M6, which patches this vulnerability by tightening the authentication logic and ensuring the asynchronous method is exclusively utilized with password or keyboard-interactive authentication.

Affected Version(s)

Apache MINA SSHD 2.0.0 < 2.20.0

Apache MINA SSHD 3.0.0-M1 < 3.0.0-M6

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chris Jarret-Davies, OpenAI Security Research Team
.