CVE-2026-49268Patch(apache / shiro)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache shiro systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users. This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • shiro

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-18); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
shiro

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-17: 1Mentions · 2026-06-18: 2Mentions · 2026-06-23: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-18: 2Technical Details · 2026-06-17: 1Technical Details · 2026-06-18: 2Technical Details · 2026-06-23: 106-1706-1806-23
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-171
Patch1
2026-06-182
Patch2
2026-06-231
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-49268: Apache Shiro: LDAP DN Injection in DefaultLdapRealm https://www.openwall.com/lists/oss-security/2026/06/17/8 bypassing authentication or impersonating other users. Fixed in 2.2.1, 3.0.0-alpha-2. Java security framework that performs authentication, authorization, cryptography, session management.

    Post summary

    CVE‑2026‑49268 is an LDAP DN injection flaw in Apache Shiro that could allow authentication bypass; a patch is available in newer releases.

    11030497
    4.7K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    A critical Apache Shiro LDAP Injection vulnerability in DefaultLdapRealm, CVE-2026-49268, allows authentication bypass. Update your framework immediately. #ApacheShiro #LDAPInjection #CyberSecurity #CVE202649268 #Vulnerability https://securityonline.info/apache-shiro-ldap-injection https://t.co/nRGxBOfH99

    Post summary

    The post highlights a critical LDAP injection flaw in Apache Shiro’s DefaultLdapRealm (CVE‑2026‑49268) and urges immediate update to mitigate the authentication bypass.

    02010302
    12.3K followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐 🚨 CRITICAL: CVE-2026-49268 — Apache Shiro LDAP Injection CVSS 9.1. Unauthenticated authentication bypass via DefaultLdapRealm. Username input directly concatenated into DN — no escaping. 🔗 https://threataft.com/articles/cve-2026-49268-apache-shiro-ldap-injection-authentication-bypass #CyberSecurity #ThreatIntel #infosec #ApacheShiro

    Post summary

    The tweet announces CVE‑2026‑49268, a critical LDAP injection flaw in Apache Shiro that allows unauthenticated authentication bypass, providing basic technical details without indicating active exploitation or mitigation.

    0000061
    31 followersView on X
  • Can Artuc@canartuc
    Patch

    Apache Shiro's DefaultLdapRealm failed to escape RFC 2253 special characters in usernames, opening an LDAP DN injection (CVE-2026-49268). Fixed in 2.2.1 and 3.0.0-alpha-2. If you authenticate against LDAP through Shiro, are you on a patched build?

    Post summary

    The notice highlights CVE-2026-49268, an LDAP DN injection flaw in Shiro’s DefaultLdapRealm, and confirms that the issue is resolved in versions 2.2.1 and 3.0.0-alpha-2, urging users to verify they are on a patched build.

    0000032
    171 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheshiro---
Appapacheshiro3.0.0--

Explore more