Bug 2543944 - CVE-2026-94052 apache-sshd: Apache MINA SSHD: LDAP password authentication ineffective [fedora-all]
Summary: CVE-2026-94052 apache-sshd: Apache MINA SSHD: LDAP password authentication in...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: apache-sshd
Version: rawhide
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ---
Assignee: Mat Booth
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["84954d5f-058a-4775-89b6-7...
Depends On:
Blocks: CVE-2026-94052
TreeView+ depends on / blocked
 
Reported: 2026-09-30 14:30 UTC by Cedric Buissart
Modified: 2026-09-30 14:30 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Cedric Buissart 2026-09-30 14:30:06 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.




Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.




sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator.




Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.


Note You need to log in before you can comment on or make changes to this bug.