logo

Critical Apache Shiro LDAP Injection Flaw Uncovered

ID: cd539634-78bc-53d5-8414-2854958a075f

STIX ID: report--cd539634-78bc-53d5-8414-2854958a075f

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Do Son

...
...

### Executive summary Security researchers disclosed CVE-2026-49268: an LDAP DN injection vulnerability in Apache Shiro's DefaultLdapRealm (affecting versions ≤2.2.0 and 3.0.0-alpha-0/alpha-1) that fails to escape RFC 2253 characters, enabling authentication bypass and impersonation; it carries a CVSS 8.8 and administrators are advised to update to 2.2.1 or 3.0.0-alpha-2 immediately. No confirmed exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.