Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems
Published Feb 9, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.36%
Description
Authentication Bypass by Alternate Name vulnerability in Apache Shiro.
This issue affects Apache Shiro: before 2.0.7.
Users are recommended to upgrade to version 2.0.7, which fixes the issue.
The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way.
Shiro 2.1.0 and later has a new parameters to remediate this issue shiro.ini: filterChainResolver.caseInsensitive = true application.properties: shiro.caseInsensitive=true
Shiro 3.0.0 and later makes this the default in shiro.ini-based configurations. Shiro 3.0.1 and later makes this the default in all configurations, including programmatic and Spring / Spring Boot.
Affected products
-
- Version 0StatusaffectedConstraints<2.0.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Shiro | unaffected |
|
No data.
Red Hat Fuse 7
shiro-web
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
shiro-web
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
shiro-web
Fix deferred
Red Hat build of Apache Camel for Spring Boot 4
shiro-web
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | shiro-web | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | shiro-web | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | shiro-web | Fix deferred | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | shiro-web | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- http://www.openwall.com/lists/oss-security/2026/02/08/1 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-23903 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2437850 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-6903 Advisory
- https://github.com/advisories/GHSA-c244-p6m5-vqj6 Advisory
- https://github.com/apache/shiro/commit/3b9638b957495004599aeaf24ba8949e309f26e8
- https://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-23903
- https://www.cve.org/CVERecord?id=CVE-2026-23903
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/02/08/1 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-23903 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2437850 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-6903 | Advisory | |
| https://github.com/advisories/GHSA-c244-p6m5-vqj6 | Advisory | |
| https://github.com/apache/shiro/commit/3b9638b957495004599aeaf24ba8949e309f26e8 | ||
| https://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k | vendor-advisoryMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-23903 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-23903 |
Change history (0)
No recorded changes yet.