CVE-2026-94052 Apache MINA SSHD sshd-ldap 认证绕过漏洞
影响攻击者可绕过 LDAP 密码认证,未授权登录 SSH 服务
Apache MINA SSHD 的 sshd-ldap 可选组件中,LdapPasswordAuthenticator 缺少必要的校验,导致认证检查可被绕过。该漏洞影响使用 sshd-ldap 并配置 LdapPasswordAuthenticator 进行密码认证的 SSH 服务端。
影响范围
Apache MINA SSHD 1.2.0 至 2.19.0,以及 3.0.0-M1 至 3.0.0-M5;仅在使用 sshd-ldap 组件并配置 LdapPasswordAuthenticator 时受影响,sshd-core 内置密码认证不受影响。
漏洞详情
漏洞类型为认证绕过。LdapPasswordAuthenticator 在处理密码认证时缺少一项检查,使得攻击者无需提供正确凭据即可通过认证。利用方式为向启用了该认证器的 SSH 服务端发起密码认证请求,从而绕过 LDAP 校验。
利用条件与风险
利用前提是目标 SSH 服务端使用 sshd-ldap 并配置了 LdapPasswordAuthenticator;一旦满足,攻击者可未授权访问,实战风险高。
修复建议
官方建议升级至 2.20.0 或 3.0.0-M6 版本;临时缓解措施暂无公开信息。
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.
Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.
sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator.
Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.