Improper Authentication in Apache Shiro - CVE-2026-56130
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to reuse a stolen authentication cookie indefinitely.
The vulnerability exists due to improper authentication in remember-me cookie handling when processing remember-me cookies on the server. A remote attacker can intercept a valid cookie and replay it after its expiration time to reuse a stolen authentication cookie indefinitely.
Only instances with RememberMe functionality enabled are vulnerable.