SB2026082594 - Multiple vulnerabilities in Apache Shiro



SB2026082594 - Multiple vulnerabilities in Apache Shiro

Published: August 25, 2026

Security Bulletin ID SB2026082594
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Session Fixation (CVE-ID: CVE-2026-43827)

CWE-ID: CWE-384 - Session Fixation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to fixate a session and hijack a user's authenticated session.

The vulnerability exists due to improper session management in the authentication session handling logic when processing a successful login for an existing session. A remote user can supply or reuse a known session identifier before login to fixate a session and hijack a user's authenticated session.

The issue occurs because an existing session is not invalidated and a new session identifier is not generated after successful login.


2) Sensitive Cookie in HTTPS Session Without 'Secure' Attribute (CVE-ID: CVE-2026-43828)

CWE-ID: CWE-614 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to expose sensitive cookie values over an insecure channel.

The vulnerability exists due to improper cookie security attribute configuration in the Shiro-native session manager and Remember-Me manager when sending JSESSIONID and rememberMe cookies in HTTPS sessions. A remote attacker can intercept cookie transmission to expose sensitive cookie values over an insecure channel.

The issue affects cookies that are sent without the Secure attribute by default.


Remediation

Install update from vendor's website.