Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-93994

CVE-2026-93994: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityHigh8.1

    High [CVE-2026-93994] Apache MINA SSHD is a Java library for client-side and server-side SSH

    CVE-2026-93994Source published Source updated

    Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD provides an equivalent configuration mechanism. In Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

    Related products — impact not confirmed
    • Apache MINA SSHD
    Source-reported affected versions
    • 2.19.0
    Source-reported fixed versions
    • 2.20.0
    • 3.0.0-M6
    Mitigation guidance
    • Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

Red Hat

1 advisory
  • Advisory severityHigh8.1

    High [CVE-2026-93994] Authentication bypass via duplicate public key presentation

    CVE-2026-93994Source published Source updated

    Authentication bypass via duplicate public key presentation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:71541 with package maven3-9-main-3.9.16-0.3.hum1. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; and 10 more.

    Related products — impact not confirmed
    • OpenShift Developer Tools and Services
    • Red Hat build of Apache Camel 4 for Quarkus 3
    • Red Hat build of Apache Camel for Spring Boot 4
    • Red Hat Enterprise Linux 10

    10 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • maven3-9-main-3.9.16-0.3.hum1
    • RHSA-2026:71541
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery