Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in Apache Shiro - CVE-2026-43828

 

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in Apache Shiro - CVE-2026-43828

Published: August 25, 2026


Vulnerability identifier: #VU145292
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43828
CWE-ID: CWE-614
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to expose sensitive cookie values over an insecure channel.

The vulnerability exists due to improper cookie security attribute configuration in the Shiro-native session manager and Remember-Me manager when sending JSESSIONID and rememberMe cookies in HTTPS sessions. A remote attacker can intercept cookie transmission to expose sensitive cookie values over an insecure channel.

The issue affects cookies that are sent without the Secure attribute by default.


Affected software

Apache Shiro

How to mitigate CVE-2026-43828

Install security update from vendor's website.

Apache Shiro - update to 2.1.1

External References

Related Security Bulletins