https://seclists.org/oss-sec/2026/q1/149: CVE-2026-23901: Apache Shiro: Brute force attack possible to determine valid user names
Published Feb 8, 2026
·Updated
Affected Software
2 affected components
Apache Shiro<2.0.7, >=1.0
maven/org.apache.shiro/shiro-core<2.0.7
Frequently Asked Questions
1
What is the severity of CVE-2026-23901?
The severity of CVE-2026-23901 is classified as low.
2
Which versions of Apache Shiro are affected by CVE-2026-23901?
CVE-2026-23901 affects Apache Shiro versions 1.* and 2.* before 2.0.7.
3
How do I fix CVE-2026-23901?
To fix CVE-2026-23901, users should upgrade to Apache Shiro version 2.0.7 or later.
4
What is the main issue described in CVE-2026-23901?
CVE-2026-23901 describes an observable timing discrepancy vulnerability in Apache Shiro.
5
What type of attack does CVE-2026-23901 allow?
CVE-2026-23901 allows brute force attacks to determine valid usernames.