8.1

CVE-2026-93994

Apache MINA SSHD: Repeated-publickey policy bypass on server

Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD provides an equivalent configuration mechanism.




In Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass.






Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt Apache MINA SSHD
Default Statusunaffected
Version 0
Version < 2.20.0
Status affected
Version 3.0.0-M1
Version < 3.0.0-M6
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.388
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Apache 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-304 Missing Critical Step in Authentication

The product implements an authentication technique, but it skips a step that weakens the technique.

https://lists.apache.org/thread.html/9t3vsm8rnvwdv9779mlg1lq2fbwojdwp
http://www.openwall.com/lists/oss-security/2026/09/29/33