Apache MINA SSHD Vulnerability Affecting SSH Authentication Mechanism
CVE-2026-93994

8.1HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-93994?

The Apache MINA SSHD library, utilized in both server-side and client-side SSH implementations, has a vulnerability within its authentication mechanism. Specifically, in versions up to 2.19.0 and 3.0.0-M1 through 3.0.0-M5, the sshd-core component fails to enforce the requirement that two public keys used for authentication must be distinct. This design flaw allows users to authenticate using the same public key presented twice, leading to a potential partial authentication bypass. To mitigate this risk, users are strongly advised to upgrade to Apache MINA SSHD version 2.20.0 or 3.0.0-M6, where this issue is addressed.

Affected Version(s)

Apache MINA SSHD 0 < 2.20.0

Apache MINA SSHD 3.0.0-M1 < 3.0.0-M6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhishek Kushwaha
.