CVE 5.9 MEDIUM

Apache Shiro: Session fixation: new session is not created after login by default_CVE-2026-43827

5.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/AU:Y/R:U/RE:L/U:Amber

Description

Default configurations of Apache Shiro have a session fixation vulnerability.

This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.

Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.

In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.

Basic Information

ID CVE-2026-43827
Source apache
Published May 25, 2026 at 20:19

Affected Product

Vendor Apache Software Foundation
Product Apache Shiro
Version 1.0
Affected Versions Apache Software Foundation Apache Shiro 1.0
Apache Software Foundation Apache Shiro 3.0.0-alpha-0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.