https://seclists.org/oss-sec/2026/q1/148: CVE-2026-23903: Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems
Published Feb 8, 2026
·Updated
Affected Software
1 affected component
Apache Shiro<2.0.7
Frequently Asked Questions
1
What is the severity of CVE-2026-23903?
The severity of CVE-2026-23903 is classified as low.
2
What versions of Apache Shiro are affected by CVE-2026-23903?
All versions of Apache Shiro before 2.0.7 are affected by CVE-2026-23903.
3
How do I fix CVE-2026-23903?
To fix CVE-2026-23903, upgrade Apache Shiro to version 2.0.7 or later.
4
What type of vulnerability is CVE-2026-23903?
CVE-2026-23903 is an Authentication Bypass by Alternate Name vulnerability.
5
When was CVE-2026-23903 published?
CVE-2026-23903 was published on February 8, 2026.