PatchSiren cyber security CVE debrief
CVE-2026-48589 Apache Software Foundation CVE debrief
Apache Shiro's Jakarta EE integration module contains an open redirect vulnerability due to insufficient validation of the HTTP Referer header when issuing post-login redirects. The vulnerability exists in the shiro-jakarta-ee module from versions 2.0-alpha through 2.2.0, and in version 3.0.0-alpha-1. The HTTP Referer header is client-controlled, and without proper validation, an attacker can influence the redirect target after authentication. This could facilitate phishing attacks by redirecting authenticated users to attacker-controlled domains. The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site).
- Vendor
- Apache Software Foundation
- Product
- Apache Shiro
- CVSS
- NONE
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-25
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-25
- Advisory updated
- 2026-07-24
Who should care
Organizations running Apache Shiro with Jakarta EE integration in production environments; security teams responsible for authentication flow review; developers maintaining Shiro-based applications.
Technical summary
The shiro-jakarta-ee module uses the HTTP Referer header to determine redirect destinations after successful authentication. Because this header is attacker-controllable and insufficiently validated, applications may redirect users to arbitrary external URLs. The vulnerability is confined to the Jakarta EE integration module and does not affect core Shiro functionality or other integration modules.
Defensive priority
medium
Recommended defensive actions
- Review applications using Apache Shiro's shiro-jakarta-ee module for affected versions (2.0-alpha through 2.2.0, 3.0.0-alpha-1)
- Upgrade to a patched version of Apache Shiro when available from the Apache Shiro project
- Implement additional server-side validation of redirect destinations independent of the Referer header
- Configure web application firewalls to detect and block suspicious redirect patterns
- Audit authentication flows for reliance on client-controlled headers for redirect decisions
Evidence notes
CVE published 2026-05-25; modified 2026-05-26. Apache Shiro security advisory confirms affected versions and Jakarta EE module scope. CVSS 4.0 vector indicates network attack vector with low attack complexity, requiring low privileges and user interaction.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48589 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48589
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48589 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48589
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://shiro.apache.org/security-reports.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.