Severity: important
CVSS 3.1: 8.1 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected versions:
- Apache MINA SSHD before 2.20.0
- Apache MINA SSHD 3.0.0-M1 before 3.0.0-M6
Description:
Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH
servers can be configured to require multi-authentication schemes, for instance
two different public keys, not just one. In OpenSSH, this would be done by
setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA
SSHD provides an equivalent configuration mechanism.
In Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server
code in component sshd-core does not enforce that the two public keys presented
are different. A user can thus successfully authenticate with only one of the
two key pairs required by presenting this single key twice. This is a partial
authentication bypass.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this
issue.
Credit:
Abhishek Kushwaha (finder)
References:
https://mina.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-93994