Apache disclosed CVE-2026-94053, a critical LDAP injection flaw in the optional sshd-ldap component of Apache MINA SSHD. SSH servers using this component for password or public-key authentication can allow unauthenticated remote login because LDAP filter metacharacters were not escaped; an attacker can authenticate with * as both the username and password. The vulnerability is rated CVSS 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) and is classified as CWE-90 and CWE-305.
Affected releases are Apache MINA SSHD 1.2.0 through 2.19.0 and 3.0.0-M1 through 3.0.0-M5, but exposure is limited to deployments that have configured sshd-ldap authentication. Organizations should identify internet-reachable and internal SSH services using this integration and upgrade to 2.20.0 or 3.0.0-M6, which escape LDAP filter parameters in accordance with RFC 4515; they should also review authentication logs for anomalous wildcard-based login attempts.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Apache documented CVE-2026-94053, a critical authentication-bypass flaw in sshd-ldap caused by unescaped LDAP filter metacharacters; vulnerable configurations could authenticate with "*" as both username and password. The issue affects sshd-ldap deployments in versions 1.2.0–2.19.0 and 3.0.0-M1–M5, and is fixed in versions 2.20.0 and 3.0.0-M6 through RFC 4515-compliant parameter escaping.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcelists.apache.org
Open sourcecve.org
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.