Back

MEDIUM

Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems

Published Feb 9, 2026

Description

Authentication Bypass by Alternate Name vulnerability in Apache Shiro.

This issue affects Apache Shiro: before 2.0.7.

Users are recommended to upgrade to version 2.0.7, which fixes the issue.

The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way.

Shiro 2.1.0 and later has a new parameters to remediate this issue shiro.ini: filterChainResolver.caseInsensitive = true application.properties: shiro.caseInsensitive=true

Shiro 3.0.0 and later makes this the default in shiro.ini-based configurations. Shiro 3.0.1 and later makes this the default in all configurations, including programmatic and Spring / Spring Boot.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Feb 9, 2026
Updated Aug 20, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated Feb 9, 2026
NVD
Status Modified
Modified Aug 20, 2026
Red Hat
Severity Moderate
Public date Feb 9, 2026
ENISA EUVD
Assigner apache
Published Feb 9, 2026
Updated Aug 20, 2026
Exploited since n/a
EUVD-2026-6903 GHSA-C244-P6M5-VQJ6