
CVE-2026-23903: Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems https://www.openwall.com/lists/oss-security/2026/02/08/1 CVE-2026-23901: Apache Shiro: Brute force attack possible to determine valid user names https://www.openwall.com/lists/oss-security/2026/02/08/2
Post summary
The brief note lists two Apache Shiro CVEs with concise vulnerability descriptions and links to Openwall mailing list discussions, but it does not provide proof of exploitation, PoC, or mitigation steps.


