Apache MINA SSHD <=2.19.0/<=3.0.0-M5: Auth Bypass via duplicate public keys
CVE-2026-93994 Published on September 30, 2026
Apache MINA SSHD: Repeated-publickey policy bypass on server
Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD provides an equivalent configuration mechanism.
In Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
Vulnerability Analysis
CVE-2026-93994 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Missing Critical Step in Authentication
The software implements an authentication technique, but it skips a step that weakens the technique. Authentication techniques should follow the algorithms that define them exactly, otherwise authentication can be bypassed or more easily subjected to brute force attacks.
Products Associated with CVE-2026-93994
Want to know whenever a new CVE is published for Apache Mina Sshd? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache MINA SSHD:- Before 2.20.0 is affected.
- Version 3.0.0-M1 and below 3.0.0-M6 is affected.