Apache Shiro: Brute force attack possible to determine valid user names
Published Feb 10, 2026
1.0
LOWCVSS 4.0
EPSS 0.22%
Description
Observable Timing Discrepancy vulnerability in Apache Shiro.
This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7.
Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue.
Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough, that a brute-force attack may be able to tell, by timing the requests only, determine if the request failed because of a non-existent user vs. wrong password.
The most likely attack vector is a local attack only. Shiro security model https://shiro.apache.org/security-model.html#username_enumeration discusses this as well.
Typically, brute force attack can be mitigated at the infrastructure level.
Affected products
-
Affected
- ≥ 0, < 2.0.7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache Shiro | unaffected | Affected
|
No data.
Red Hat Fuse 7
shiro-core
Fix deferred
Red Hat JBoss Enterprise Application Platform 7
shiro-core
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
shiro-core
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
shiro-core
Fix deferred
Red Hat build of Apache Camel for Spring Boot 4
shiro-core
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | shiro-core | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | shiro-core | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | shiro-core | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | shiro-core | Fix deferred | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | shiro-core | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- http://www.openwall.com/lists/oss-security/2026/02/08/2 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-23901 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2438436 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-6879 Advisory
- https://github.com/advisories/GHSA-c4qc-4q9p-m9q9 Advisory
- https://lists.apache.org/thread/mm1jct9b86jvnh3y44tj22xvjtx3xhhh vendor-advisoryIssue TrackingMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-23901
- https://www.cve.org/CVERecord?id=CVE-2026-23901
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/02/08/2 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-23901 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2438436 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-6879 | Advisory | |
| https://github.com/advisories/GHSA-c4qc-4q9p-m9q9 | Advisory | |
| https://lists.apache.org/thread/mm1jct9b86jvnh3y44tj22xvjtx3xhhh | vendor-advisoryIssue TrackingMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-23901 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-23901 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub