This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.
Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.
In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 28 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:* cpe:2.3:a:apache:shiro:3.0.0:alpha1:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache shiro |
|
| Vendors & Products |
Apache
Apache shiro |
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 26 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID. | |
| Title | Apache Shiro: Session fixation: new session is not created after login by default | |
| Weaknesses | CWE-384 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-05-26T12:39:39.186Z
Reserved: 2026-05-02T22:26:19.626Z
Link: CVE-2026-43827
Updated: 2026-05-25T21:26:12.053Z
Status : Analyzed
Published: 2026-05-25T21:16:34.700
Modified: 2026-06-17T10:49:58.950
Link: CVE-2026-43827
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:05:56Z