Apache MINA SSHD Vulnerability Affecting SSH Authentication Mechanism
CVE-2026-93994
8.1HIGH
What is CVE-2026-93994?
The Apache MINA SSHD library, utilized in both server-side and client-side SSH implementations, has a vulnerability within its authentication mechanism. Specifically, in versions up to 2.19.0 and 3.0.0-M1 through 3.0.0-M5, the sshd-core component fails to enforce the requirement that two public keys used for authentication must be distinct. This design flaw allows users to authenticate using the same public key presented twice, leading to a potential partial authentication bypass. To mitigate this risk, users are strongly advised to upgrade to Apache MINA SSHD version 2.20.0 or 3.0.0-M6, where this issue is addressed.
Affected Version(s)
Apache MINA SSHD 0 < 2.20.0
Apache MINA SSHD 3.0.0-M1 < 3.0.0-M6