CVE-2026-23903Disclosure(apache / shiro)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache shiro systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way. Shiro 2.1.0 and later has a new parameters to remediate this issue shiro.ini: filterChainResolver.caseInsensitive = true application.properties: shiro.caseInsensitive=true Shiro 3.0.0 and later makes this the default in shiro.ini-based configurations. Shiro 3.0.1 and later makes this the default in all configurations, including programmatic and Spring / Spring Boot.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-289

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • shiro

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-09)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
shiro

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-08: 1Mentions · 2026-02-09: 2Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 202-0802-09
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-081
Disclosure1
2026-02-092
Disclosure1Patch1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-23903: Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems https://www.openwall.com/lists/oss-security/2026/02/08/1 CVE-2026-23901: Apache Shiro: Brute force attack possible to determine valid user names https://www.openwall.com/lists/oss-security/2026/02/08/2

    Post summary

    The brief note lists two Apache Shiro CVEs with concise vulnerability descriptions and links to Openwall mailing list discussions, but it does not provide proof of exploitation, PoC, or mitigation steps.

    00032481
    4.4K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23903 Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.… https://www.cve.org/CVERecord?id=CVE-2026-23903

    Post summary

    The notice highlights an authentication bypass flaw in Apache Shiro, advises upgrading to version 2.0.7 or later, and links to the CVE record.

    00010267
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23903 Authentication Bypass in Apache Shiro Before Version 2.0.7 via Case-Insensitive Filesystem https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23903

    Post summary

    A case‑insensitive filesystem flaw allows authentication bypass in Apache Shiro versions earlier than 2.0.7, but no PoC, exploit code, or active exploitation details are mentioned.

    0000056
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheshiro---

Explore more