
CVE-2026-49268: Apache Shiro: LDAP DN Injection in DefaultLdapRealm https://www.openwall.com/lists/oss-security/2026/06/17/8 bypassing authentication or impersonating other users. Fixed in 2.2.1, 3.0.0-alpha-2. Java security framework that performs authentication, authorization, cryptography, session management.
Post summary
CVE‑2026‑49268 is an LDAP DN injection flaw in Apache Shiro that could allow authentication bypass; a patch is available in newer releases.



