SB2026082594 - Multiple vulnerabilities in Apache Shiro
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Session Fixation (CVE-ID: CVE-2026-43827)
CWE-ID: CWE-384 - Session Fixation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to fixate a session and hijack a user's authenticated session.
The vulnerability exists due to improper session management in the authentication session handling logic when processing a successful login for an existing session. A remote user can supply or reuse a known session identifier before login to fixate a session and hijack a user's authenticated session.
The issue occurs because an existing session is not invalidated and a new session identifier is not generated after successful login.
2) Sensitive Cookie in HTTPS Session Without 'Secure' Attribute (CVE-ID: CVE-2026-43828)
CWE-ID: CWE-614 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to expose sensitive cookie values over an insecure channel.
The vulnerability exists due to improper cookie security attribute configuration in the Shiro-native session manager and Remember-Me manager when sending JSESSIONID and rememberMe cookies in HTTPS sessions. A remote attacker can intercept cookie transmission to expose sensitive cookie values over an insecure channel.
The issue affects cookies that are sent without the Secure attribute by default.
Remediation
Install update from vendor's website.