CVE-2026-94053 Overview
CVE-2026-94053 is an authentication bypass vulnerability in the optional sshd-ldap component of Apache MINA SSHD. The flaw affects versions 1.2.0 through 2.19.0 and 3.0.0-M1 through 3.0.0-M5. Apache MINA SSHD is a Java library providing client-side and server-side SSH functionality, and sshd-ldap integrates password and public key authentication with a Lightweight Directory Access Protocol (LDAP) server. The component fails to escape LDAP filter metacharacters, allowing an attacker to authenticate successfully by supplying the username * and password *. Only SSH servers that deploy sshd-ldap and configure it for password or public key authentication are affected.
Critical Impact
Unauthenticated remote attackers can bypass authentication and gain SSH access by submitting wildcard credentials against servers using the sshd-ldap component.
Affected Products
- Apache MINA SSHD versions 1.2.0 through 2.19.0 (when sshd-ldap is configured for authentication)
- Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M5 (when sshd-ldap is configured for authentication)
- Java applications embedding Apache MINA SSHD with LDAP-backed password or public key authentication
Discovery Timeline
- 2026-09-30 - CVE-2026-94053 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-94053
Vulnerability Analysis
The vulnerability is classified under CWE-90: Improper Neutralization of Special Elements used in an LDAP Query. The sshd-ldap component constructs LDAP search filters using user-supplied credentials without escaping filter metacharacters. According to the Apache advisory, submitting the username * and password * produces an LDAP filter that matches any directory entry, allowing authentication to succeed against an arbitrary account.
An attacker who reaches an affected SSH service over the network can bypass authentication without prior credentials or user interaction. Once authenticated, the attacker inherits the privileges of the matched LDAP account, which frequently maps to shell access, file transfer, or downstream service integration. The impact scales with the privilege of accounts exposed through the LDAP directory.
Root Cause
The root cause is missing input sanitization when building LDAP search filters. LDAP filter syntax defined in RFC 4515 treats characters such as *, (, ), \, and NUL as metacharacters. The vulnerable versions concatenate user input directly into the filter string, so a wildcard character in the username or password is interpreted as an LDAP wildcard rather than a literal value. The fix applied in 2.20.0 and 3.0.0-M6 escapes these characters according to RFC 4515.
Attack Vector
Exploitation requires only network reachability to an SSH server that has enabled sshd-ldap for password or public key authentication. The attacker initiates a standard SSH connection, presents the username *, and submits the password *. The malformed filter returned by the LDAP server matches an entry, and the SSH server grants access. No prior credentials, tokens, or session state are required. See the Apache Security Mailing List Thread and the Openwall OSS-Security Discussion for the vendor's technical description.
Detection Methods for CVE-2026-94053
Indicators of Compromise
- SSH authentication events where the submitted username is literally * or contains unescaped LDAP metacharacters such as (, ), or \.
- Successful SSH logins from unexpected source addresses that immediately follow failed enumeration attempts against the same service.
- LDAP server query logs showing search filters containing wildcard uid=* or equivalent patterns originating from the SSH host.
Detection Strategies
- Inspect application logs from services embedding Apache MINA SSHD for authentication attempts with non-standard usernames, and correlate with the version of sshd-ldap in use.
- Enable verbose logging on the backing LDAP directory and alert on search filters that resolve to more than one entry during authentication binds.
- Review SSH session records for accounts that were accessed without a corresponding legitimate user activity pattern.
Monitoring Recommendations
- Monitor egress and ingress SSH traffic to hosts that run Java services with LDAP-backed authentication.
- Track process and dependency inventories to identify Java applications shipping vulnerable sshd-ldap JAR versions.
- Alert on any LDAP bind or search operation initiated by the SSH server that returns multiple candidate entries for a single authentication attempt.
How to Mitigate CVE-2026-94053
Immediate Actions Required
- Upgrade Apache MINA SSHD to version 2.20.0 or 3.0.0-M6, which escape LDAP filter parameters per RFC 4515.
- Audit all Java applications for the presence of the sshd-ldap artifact and confirm whether it is configured for password or public key authentication.
- Rotate credentials for any LDAP account that may have been exposed through an affected SSH service.
- Review authentication and LDAP query logs for evidence of exploitation using wildcard credentials.
Patch Information
The Apache MINA project fixed the flaw by properly escaping filter parameters according to RFC 4515. Upgrade to 2.20.0 for the 2.x branch or 3.0.0-M6 for the 3.x branch. Details are published in the Apache Security Mailing List Thread.
Workarounds
- Disable the sshd-ldap component and switch to an alternative authenticator until the upgrade is applied.
- Restrict network access to SSH services that use sshd-ldap with firewall rules or bastion controls limiting traffic to trusted management networks.
- Enforce input validation at the SSH front end to reject usernames containing LDAP metacharacters such as *, (, ), or \.
# Example Maven dependency update to the fixed version
<dependency>
<groupId>org.apache.sshd</groupId>
<artifactId>sshd-ldap</artifactId>
<version>2.20.0</version>
</dependency>
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
