THREAT OPS › Threat News › [NVD] CVE-2026-23903 (MEDIUM 5.3) — Authentication Bypass by Alternate Name vulnerability in Apache Shiro.
This issue affects Apache Shiro: before 2.0.7.
Users are recommended to upgrade to version 2.0.7, which fixes the issue.
The issue only effects static files. If static files are served from a case-insensiti
[NVD] CVE-2026-23903 (MEDIUM 5.3) — Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensiti
CVE-2026-23903 CVSS: 5.3 MEDIUM Published: 2026-02-09T10:15:57.520
Authentication Bypass by Alternate Name vulnerability in Apache Shiro.
This issue affects Apache Shiro: before 2.0.7.
Users are recommended to upgrade to version 2.0.7, which fixes the issue.
The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static f
Indicators of compromise
- CVE-2026-23903cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-23903