
CVE-2026-23903: Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems https://www.openwall.com/lists/oss-security/2026/02/08/1 CVE-2026-23901: Apache Shiro: Brute force attack possible to determine valid user names https://www.openwall.com/lists/oss-security/2026/02/08/2
Post summary
The text announces two new Apache Shiro vulnerabilities: CVE-2026-23903, an authentication bypass on case‑insensitive filesystems, and CVE-2026-23901, a brute‑force attack for username enumeration.

