Skip to main content
Vulnerability Database/CVE-2026-77185

CVE-2026-77185: Apache MINA SSHD Auth Bypass Vulnerability

CVE-2026-77185 is an authentication bypass flaw in Apache MINA SSHD that affects asynchronous authentication implementation. This vulnerability could allow attackers to skip signature verification in public-key or hostbased authentication. This post explains its technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-77185 Overview

CVE-2026-77185 is an authentication bypass vulnerability in the sshd-core component of Apache MINA SSHD, a Java library for building SSH clients and servers. The flaw affects versions 2.0.0 through 2.19.0 and 3.0.0-M1 through 3.0.0-M5. The bug lives in the server-side "asynchronous authentication" mechanism. When a server implementation opts into this feature, the flawed logic can skip signature verification during public-key or hostbased authentication, or return an incorrect authentication result. The vulnerability is categorized under [CWE-305: Authentication Bypass by Primary Weakness].

Critical Impact

An unauthenticated remote attacker may bypass SSH public-key or hostbased authentication against vulnerable servers that implement asynchronous authentication, gaining unauthorized session access.

Affected Products

  • Apache MINA SSHD sshd-core versions 2.0.0 through 2.19.0
  • Apache MINA SSHD sshd-core versions 3.0.0-M1 through 3.0.0-M5
  • Any downstream SSH server built on Apache MINA SSHD that implements the asynchronous authentication callback

Discovery Timeline

  • 2026-09-30 - CVE-2026-77185 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-77185

Vulnerability Analysis

Apache MINA SSHD provides an optional "asynchronous authentication" API. A server developer must write explicit code to enable it, which limits the population of exposed deployments. When enabled, the server defers the authentication decision to an asynchronous callback rather than resolving it inline within the SSH transport handler.

The defect is a control-flow error in how the asynchronous path handles public-key and hostbased authentication requests. In these schemes the server must verify a cryptographic signature over session-bound data to prove the client controls the private key. The flawed implementation can proceed past the signature check without evaluating it, or propagate an incorrect boolean result back to the SSH state machine. Either outcome allows a client that presents only a public key, without a valid signature, to be treated as authenticated.

Root Cause

The root cause is a logic error in the asynchronous authentication handler within sshd-core. The handler was designed for password and keyboard-interactive schemes, where authentication reduces to a single credential comparison. Public-key and hostbased authentication instead require a two-phase exchange: an initial key presentation followed by a signed verification message. The asynchronous code path did not correctly gate the final authentication result on the signature verification step, resulting in an [CWE-305] primary weakness bypass.

Attack Vector

Exploitation requires network reach to an SSH server built on a vulnerable Apache MINA SSHD version that has explicitly wired the asynchronous authentication API into its public-key or hostbased flow. An attacker initiates an SSH connection, selects publickey or hostbased as the authentication method, and submits a public key belonging to a valid user. The attacker does not need the corresponding private key. Because the server may skip or misreport signature verification, the connection can be authorized. No user interaction is required and the attacker needs no prior credentials. Refer to the Apache Mailing List Discussion and the OpenWall OSS Security Update for maintainer details.

Detection Methods for CVE-2026-77185

Indicators of Compromise

  • SSH authentication success events for publickey or hostbased methods that lack a corresponding preceding signature verification log entry.
  • Successful sessions from source addresses that have never previously enrolled or used the presented key.
  • Server log entries introduced in the fixed versions warning that asynchronous authentication was attempted with public-key or hostbased schemes.

Detection Strategies

  • Inventory all Java applications that embed org.apache.sshd:sshd-core and identify any that register an asynchronous authenticator via the server builder API.
  • Review server logs for authentication events lacking matched signature-verification traces, and correlate with source IP, username, and key fingerprint.
  • Instrument the SSH server to emit an audit event on every completed public-key authentication, including the fingerprint of the verified key.

Monitoring Recommendations

  • Forward SSH server logs to a centralized analytics platform and alert on public-key authentications from previously unseen source and key-fingerprint pairs.
  • Monitor for connections that complete authentication in fewer round-trips than expected for the negotiated method.
  • Track deployment inventory of sshd-core versions and alert on any host still running a version between 2.0.0 and 2.19.0 or between 3.0.0-M1 and 3.0.0-M5.

How to Mitigate CVE-2026-77185

Immediate Actions Required

  • Upgrade sshd-core to Apache MINA SSHD 2.20.0 or 3.0.0-M6 in all embedding applications and rebuild dependent artifacts.
  • If upgrade is not immediately possible, disable the asynchronous authenticator registration in server initialization code and fall back to synchronous authentication.
  • Rotate any SSH keys and credentials associated with exposed servers, and audit recent session logs for unauthorized access.

Patch Information

Apache has released fixed versions 2.20.0 and 3.0.0-M6. These releases correct the asynchronous authentication logic and additionally forbid the use of the asynchronous authentication mechanism with public-key or hostbased authentication schemes. If a server attempts this combination, the SSH session is closed and the server logs an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication. Details are available in the Apache Mailing List Discussion.

Workarounds

  • Remove the asynchronous authentication callback from server configuration and rely on the synchronous PublickeyAuthenticator interface.
  • Restrict SSH server exposure to trusted network segments using firewall rules or a bastion host until the library is upgraded.
  • Enforce additional access controls such as mutual TLS at a reverse proxy or SSH connection allowlisting while patch deployment is in progress.
bash
# Maven dependency upgrade example
# Update the sshd-core coordinate in your pom.xml
# <dependency>
#   <groupId>org.apache.sshd</groupId>
#   <artifactId>sshd-core</artifactId>
#   <version>2.20.0</version>
# </dependency>
mvn versions:use-dep-version -Dincludes=org.apache.sshd:sshd-core -DdepVersion=2.20.0 -DforceVersion=true
mvn dependency:tree | grep sshd-core

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.