Apache MINA SSHD: Critical LDAP auth bypass CVE-2026-94053/94052 (CVSS 9.1) + SFTP DoS; fix 2.20.0 / 3.0.0-M6
Apache MINA SSHD maintainers (oss-security, 29 September 2026; CVE records published 30 Sep) disclose critical flaws in the optional sshd-ldap component plus related SFTP memory issues, fixed in 2.20.0 and 3.0.0-M6. CVE-2026-94053 (CVSS 3.1 9.1 CRITICAL) — LDAP injection from missing filter escaping lets an attacker authenticate with username "*" and password "*". CVE-2026-94052 (CVSS 3.1 9.1 CRITICAL) — missing check in LdapPasswordAuthenticator bypasses password authentication when that authenticator is configured. Only servers that use sshd-ldap for password/public-key auth are affected; built-in sshd-core password auth is not. Also: CVE-2026-94029 (CVSS 3.1 6.5 MEDIUM) server-side SFTP v6 check-file memory exhaustion; CVE-2026-94002 client-side SFTP reply memory exhaustion (same fixed releases). Credit: Dilrevx, Ho1aAs. Primary: Apache oss-security 29 Sep; wire: CVE.report 30 Sep.
- Product
- Apache MINA SSHD (optional sshd-ldap; sshd-sftp)
- Versions
- LDAP issues (94053/94052): Apache MINA SSHD 1.2.0 through 2.19.0 and 3.0.0-M1 through 3.0.0-M5 when sshd-ldap is configured for auth. SFTP DoS 94029: 1.0.0–2.19.0 and 3.0.0-M1–M5. Client SFTP 94002: 0.9.0–2.19.0 and 3.0.0-M1–M5. Fixed: 2.20.0 and 3.0.0-M6.
- CVSS
- / 9.1 / 6.5 (CVSS 3.1: 94053 CRITICAL, 94052 CRITICAL, 94029 MEDIUM; 94002 see CVE record)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (94053 & 94052); CVSS:3.1 - Exploited in Australia?
- unknown
- Patch to
- Upgrade Apache MINA SSHD to 2.20.0 or 3.0.0-M6. If you cannot patch immediately, disable sshd-ldap / LdapPasswordAuthenticator and avoid exposing MINA SSHD SFTP to untrusted peers. Confirm whether your product embeds MINA SSHD with LDAP auth enabled.
Primary: oss-security — CVE-2026-94053 Apache MINA SSHD LDAP injection (29 Sep 2026) · Vendor: Apache MINA project · CVE: CVE-2026-94053, CVE-2026-94052, CVE-2026-94029, CVE-2026-94002 · CVE.report — CVE-2026-94053 (published 30 Sep 2026)
