CVE-2026-93994 Apache MINA SSHD 多因素认证绕过漏洞
影响攻击者可用单个密钥绕过双公钥多因素认证
Apache MINA SSHD 是用于客户端和服务端的 Java SSH 库,支持配置多因素认证(如要求两个不同公钥)。在受影响版本中,sshd-core 服务端代码未校验两次提交的公钥是否不同,导致认证逻辑存在缺陷。攻击者只需重复提交同一密钥即可通过本应需要两把密钥的认证流程。
影响范围
Apache MINA SSHD 2.19.0 及之前版本,以及 3.0.0-M1 至 3.0.0-M5 版本。
漏洞详情
该漏洞属于认证绕过(部分认证绕过)。当服务端配置要求两个公钥(等价于 OpenSSH 的 AuthenticationMethods "publickey,publickey")时,代码未强制两次提供的公钥必须不同。攻击者只需持有其中一把合法密钥,将其提交两次,即可满足多因素认证要求,从而绕过第二把密钥的验证。
利用条件与风险
利用前提是目标服务端启用了需要两个不同公钥的多因素认证配置,且攻击者已持有一把合法密钥。实战中会导致多因素认证强度被削弱为单因素,提升未授权访问风险。
修复建议
官方建议升级至 2.20.0 或 3.0.0-M6 版本以修复该问题;在无法升级时,可临时避免依赖双公钥多因素认证配置,或改用其他认证方式组合。
Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods “publickey,publickey”. Apache MINA SSHD provides an equivalent configuration mechanism.
In Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.