PatchSiren cyber security CVE debrief
CVE-2026-23903 Apache CVE debrief
CVE-2026-23903 is an Authentication Bypass by Alternate Name vulnerability in Apache Shiro before version 2.0.7. This issue affects static files served from case-insensitive filesystems, allowing access by varying filename case in requests. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users are recommended to upgrade to version 2.0.7 or configure case insensitivity parameters in shiro.ini or application.properties. Shiro 2.1.0 and later versions offer a parameter to remediate this issue: shiro.ini: filterChainResolver.caseInsensitive = true or application.properties: shiro.caseInsensitive=true. This is the default in Shiro 3.0.1 and later configurations. Apache Shiro users, especially those serving static files from case-insensitive filesystems, should be aware of this vulnerability and take action to upgrade or configure their systems.
- Vendor
- Apache
- Product
- Shiro
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-09
- Original CVE updated
- 2026-08-20
- Advisory published
- 2026-02-09
- Advisory updated
- 2026-08-20
Who should care
Apache Shiro users, especially those serving static files from case-insensitive filesystems, should be aware of this vulnerability and take action to upgrade or configure their systems. Users of Shiro 2.1.0 and later should configure case insensitivity parameters to remediate this issue. Security teams and operators managing Shiro deployments should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. Those with confirmed exposure should plan vendor-supported updates or mitigations through normal change control and review compensating controls for exposed systems.
Technical summary
CVE-2026-23903 is an Authentication Bypass by Alternate Name vulnerability in Apache Shiro before version 2.0.7. The issue affects static files served from case-insensitive filesystems, allowing access by varying filename case in requests. Users should upgrade to 2.0.7 or configure case insensitivity parameters in shiro.ini or application.properties. Shiro 2.1.0 and later versions offer a parameter to remediate this issue: shiro.ini: filterChainResolver.caseInsensitive = true or application.properties: shiro.caseInsensitive=true. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way.
Defensive priority
Apache Shiro users should prioritize upgrading to version 2.0.7 or later to address the authentication bypass vulnerability.
Recommended defensive actions
- Upgrade Apache Shiro to version 2.0.7 or later
- Configure Shiro 2.1.0 and later with filterChainResolver.caseInsensitive = true or shiro.caseInsensitive=true
- Monitor for unusual file access patterns on case-insensitive filesystems
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE-2026-23903 record indicates an Authentication Bypass by Alternate Name vulnerability in Apache Shiro before version 2.0.7. The issue allows static files to be accessed by varying the case of the filename in the request on case-insensitive filesystems. Users are recommended to upgrade to version 2.0.7. Shiro 2.1.0 and later versions offer a parameter to remediate this issue: shiro.ini: filterChainResolver.caseInsensitive = true or application.properties: shiro.caseInsensitive=true. This is the default in Shiro 3.0.1 and later configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23903 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23903
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23903 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23903
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k
[email protected] - Mailing List, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.