Critical Apache Shiro LDAP Injection Flaw Uncovered
ID: cd539634-78bc-53d5-8414-2854958a075f
STIX ID: report--cd539634-78bc-53d5-8414-2854958a075f
Feed Name: securityonline.info
Threat Score
### Executive summary Security researchers disclosed CVE-2026-49268: an LDAP DN injection vulnerability in Apache Shiro's DefaultLdapRealm (affecting versions ≤2.2.0 and 3.0.0-alpha-0/alpha-1) that fails to escape RFC 2253 characters, enabling authentication bypass and impersonation; it carries a CVSS 8.8 and administrators are advised to update to 2.2.1 or 3.0.0-alpha-2 immediately. No confirmed exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
