CVE-2026-43827: Apache Shiro: Session fixation: new session is not created after login by default
Default configurations of Apache Shiro have a session fixation vulnerability.
This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.
Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.
In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Shiroto a version that resolves this vulnerability.Fixed in 2.1.1 - Upgrade
Upgrade
Apache Shiroto a version that resolves this vulnerability.Fixed in 3.0.0-alpha-2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43827?
The severity of CVE-2026-43827 is medium with a CVSS score of 5.9.
How do I fix CVE-2026-43827?
To fix CVE-2026-43827, upgrade Apache Shiro to version 2.1.1 or 3.0.0-alpha-2 or later.
What software is affected by CVE-2026-43827?
CVE-2026-43827 affects Apache Shiro versions 1.0 to 2.1.0 and 3.0.0-alpha-1.
What is the nature of the vulnerability in CVE-2026-43827?
CVE-2026-43827 is a session fixation vulnerability where a new session is not created after login by default.
When was CVE-2026-43827 published?
CVE-2026-43827 was published on May 25, 2026.