LDAP injection in Apache Shiro - CVE-2026-49268
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication or impersonate other users.
The vulnerability exists due to improper neutralization of special elements in the distinguished name construction in DefaultLdapRealm when processing user-supplied username input for LDAP bind authentication. A remote attacker can supply a username containing LDAP special characters to bypass authentication or impersonate other users.
Only configurations using DefaultLdapRealm are vulnerable.