Skip to main content
Vulnerability Database/CVE-2026-93994

CVE-2026-93994: Apache MINA SSHD Auth Bypass Vulnerability

CVE-2026-93994 is an authentication bypass flaw in Apache MINA SSHD that allows users to bypass multi-authentication by presenting the same key twice. This post covers technical details, affected versions, and mitigation steps.

Published:

CVE-2026-93994 Overview

Apache MINA SSHD contains a partial authentication bypass in its multi-factor public key authentication logic. The Java SSH library allows administrators to require multiple public keys for authentication, similar to OpenSSH's AuthenticationMethods "publickey,publickey" configuration. In affected versions, the sshd-core server component does not verify that the two public keys presented during authentication are distinct. An attacker holding a single valid key pair can satisfy both authentication steps by presenting the same key twice, defeating the multi-key requirement [CWE-304].

Critical Impact

A user with a single valid key pair can bypass multi-key SSH authentication requirements, gaining access intended only for holders of two distinct keys.

Affected Products

  • Apache MINA SSHD versions up to and including 2.19.0
  • Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5
  • The sshd-core server component

Discovery Timeline

  • 2026-09-30 - CVE-2026-93994 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-93994

Vulnerability Analysis

Apache MINA SSHD is a Java library implementing both client-side and server-side SSH functionality. Server operators can configure multi-factor public key authentication, requiring an SSH client to prove possession of two separate private keys before granting access. This mirrors OpenSSH behavior configured through the AuthenticationMethods publickey,publickey directive.

The server-side implementation in sshd-core accepts two successive public key authentication attempts but omits a uniqueness check between them. When a client submits the same public key for both authentication stages, the server treats each submission as a valid, independent factor. The result is a partial authentication bypass: one key satisfies a policy that intended to require two.

This weakness falls under [CWE-304] (Missing Critical Step in Authentication). The impact affects confidentiality and integrity of authenticated sessions but does not directly enable denial of service.

Root Cause

The authentication state machine in the affected sshd-core versions tracks whether public key authentication succeeded but does not record which key was used. Consequently, the second publickey step cannot detect reuse of the first key. The fix, delivered in versions 2.20.0 and 3.0.0-M6, adds enforcement that the two public keys presented must differ.

Attack Vector

Exploitation requires network access to the SSH service and possession of one valid private key associated with a user configured for multi-key authentication. The attacker connects to the server, completes the first publickey authentication using the valid key, then repeats the same key for the second required factor. The server accepts the duplicate submission and grants an authenticated session.

No public exploit code is currently available. Technical detail is provided in the Apache Mailing List Thread and the Openwall OSS-Security Update.

Detection Methods for CVE-2026-93994

Indicators of Compromise

  • SSH authentication events where the same public key fingerprint appears twice in a single session negotiation.
  • Successful logins to accounts configured for multi-key authentication when only one distinct key fingerprint is recorded in the audit log.
  • Unexpected authenticated sessions on services running vulnerable Apache MINA SSHD versions.

Detection Strategies

  • Enable verbose SSH authentication logging in the MINA SSHD server and correlate the public key fingerprints presented during each authentication stage.
  • Inventory Java applications and appliances embedding sshd-core and check the packaged version against 2.20.0 and 3.0.0-M6.
  • Compare authentication attempts against expected policy: any session satisfying a multi-key requirement with a single fingerprint is suspicious.

Monitoring Recommendations

  • Forward SSH authentication logs to a central analytics platform and alert on duplicate key fingerprints within one session.
  • Track version metadata of embedded SSH libraries as part of software bill of materials (SBOM) monitoring.
  • Baseline normal authentication key usage per account and flag sessions that deviate from the configured multi-key pattern.

How to Mitigate CVE-2026-93994

Immediate Actions Required

  • Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6 on all servers using sshd-core with multi-key authentication.
  • Identify third-party products that bundle vulnerable MINA SSHD versions and apply vendor updates as they become available.
  • Rotate SSH keys for accounts protected by multi-key policies if compromise is suspected.

Patch Information

The Apache MINA project fixed this issue in sshd-core versions 2.20.0 and 3.0.0-M6. The patch adds a check ensuring that the public keys presented across successive authentication stages are distinct. Refer to the Apache Mailing List Thread for release details.

Workarounds

  • If patching is not immediately feasible, remove the multi-key publickey,publickey configuration and enforce a different second factor such as keyboard-interactive or password authentication.
  • Restrict network exposure of vulnerable SSH endpoints using firewall rules or bastion hosts until upgrades complete.
  • Audit authorized_keys files and remove any keys that should not grant standalone access.
bash
# Verify installed Apache MINA SSHD version in a Java project
mvn dependency:tree | grep sshd-core

# Or for Gradle-based builds
gradle dependencies | grep sshd-core

# Upgrade coordinates (Maven)
# <dependency>
#   <groupId>org.apache.sshd</groupId>
#   <artifactId>sshd-core</artifactId>
#   <version>2.20.0</version>
# </dependency>

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.