CVE-2026-23901Disclosure(apache / shiro)

LOWCVSS 2.5 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough, that a brute-force attack may be able to tell, by timing the requests only, determine if the request failed because of a non-existent user vs. wrong password. The most likely attack vector is a local attack only. Shiro security model  https://shiro.apache.org/security-model.html#username_enumeration  discusses this as well. Typically, brute force attack can be mitigated at the infrastructure level.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • shiro

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
shiro

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-08: 1Mentions · 2026-02-10: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-10: 102-0802-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-23903: Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems https://www.openwall.com/lists/oss-security/2026/02/08/1 CVE-2026-23901: Apache Shiro: Brute force attack possible to determine valid user names https://www.openwall.com/lists/oss-security/2026/02/08/2

    Post summary

    The text announces two new Apache Shiro vulnerabilities: CVE-2026-23903, an authentication bypass on case‑insensitive filesystems, and CVE-2026-23901, a brute‑force attack for username enumeration.

    00032481
    4.4K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-23901: The Telltale Heartbeat: Timing Leaks in Apache Shiro Apache Shiro, a ubiquitous Java security framework, inadvertently implemented a classic side-channel vulnerability: the timing oracle. By optimizing the authentication flow to 'fail ... https://cvereports.com/reports/CVE-2026-23901

    Post summary

    The report discloses a timing‑oracle side‑channel flaw in Apache Shiro’s authentication flow, providing technical details but no PoC, exploit, patch, or evidence of active exploitation.

    0000033
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheshiro---

Explore more