CVE-2026-93994
CVE-2026-93994: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityHigh8.1
High [CVE-2026-93994] Apache MINA SSHD is a Java library for client-side and server-side SSH
CVE-2026-93994Source published Source updated
Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". Apache MINA SSHD provides an equivalent configuration mechanism. In Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
- Related products — impact not confirmed
- Apache MINA SSHD
- Source-reported affected versions
- 2.19.0
- Source-reported fixed versions
- 2.20.0
- 3.0.0-M6
- Mitigation guidance
- Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
Red Hat
1 advisory- Advisory severityHigh8.1
High [CVE-2026-93994] Authentication bypass via duplicate public key presentation
CVE-2026-93994Source published Source updated
Authentication bypass via duplicate public key presentation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:71541 with package maven3-9-main-3.9.16-0.3.hum1. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; and 10 more.
- Related products — impact not confirmed
- OpenShift Developer Tools and Services
- Red Hat build of Apache Camel 4 for Quarkus 3
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat Enterprise Linux 10
10 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- maven3-9-main-3.9.16-0.3.hum1
- RHSA-2026:71541
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.