Improper access control in Apache Shiro - CVE-2026-56091
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper access control in the shiro-guice module when handling a specially crafted HTTP request in a web servlet context. A remote attacker can send a specially crafted HTTP request to bypass authentication.
Only deployments using the shiro-guice module in a web servlet context are vulnerable.