
CVE-2026-43827 CVE-2026-43827 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43827
Post summary
The content only mentions the CVE identifier and provides a link to a vulnerability database, with no further details.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

CVE-2026-43827 CVE-2026-43827 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43827
Post summary
The content only mentions the CVE identifier and provides a link to a vulnerability database, with no further details.
2 of 2 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | apache | shiro | - | - | - |
| App | apache | shiro | 3.0.0 | - | - |