VYPR
Medium severity6.5NVD Advisory· Published May 25, 2026· Updated Jul 24, 2026

CVE-2026-43827

CVE-2026-43827

Description

Default configurations of Apache Shiro have a session fixation vulnerability.

This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.

Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.

In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.shiro:shiro-coreMaven
>= 1.0.0-incubating, < 2.2.02.2.0
org.apache.shiro:shiro-coreMaven
>= 3.0.0-alpha-1, < 3.0.0-alpha-23.0.0-alpha-2

Affected products

4
  • Apache/Shiroinferred4 versions
    >=1.0,<=2.1.0 || =3.0.0-alpha-1+ 3 more
    • (no CPE)range: >=1.0,<=2.1.0 || =3.0.0-alpha-1
    • cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*range: <2.1.1
    • cpe:2.3:a:apache:shiro:3.0.0:alpha1:*:*:*:*:*:*
    • (no CPE)range: 1.0 - 2.1.0, 3.0.0-alpha-1

Patches

Vulnerability mechanics

References

4

News mentions

1