Session Fixation in Apache Shiro - CVE-2026-43827
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to fixate a session and hijack a user's authenticated session.
The vulnerability exists due to improper session management in the authentication session handling logic when processing a successful login for an existing session. A remote user can supply or reuse a known session identifier before login to fixate a session and hijack a user's authenticated session.
The issue occurs because an existing session is not invalidated and a new session identifier is not generated after successful login.