Server Misconfiguration in Apache Shiro's Jakarta EE Module
CVE-2026-58301
5.9MEDIUM
What is CVE-2026-58301?
A vulnerability exists in Apache Shiro when used with the Jakarta EE integration module. A low-privileged user can exploit this issue by crafting a malicious HTTP request, which leads the server to connect to an attacker-controlled URL. This may result in unintended data transmission to the attacker, compromising the integrity and confidentiality of the application's data. Users are advised to upgrade to version 3.0.1 or higher to mitigate this risk. Additionally, setting specific system properties can restrict connections made during form resubmissions, enhancing security further.
Affected Version(s)
Apache Shiro 2.0.0-alpha-0 <= 3.0.0
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
liyi.zhou@sydney.edu.au (Liyi), https://lzhou1110.github.io/
ziyue0530@gmail.com (Ziyue), https://zyy0530.github.io/
cshe0476@uni.sydney.edu.au (Strick), https://str1ckl4nd.github.io/
chng0012@uni.sydney.edu.au (Maurice), http://maurice.busystar.org/
cyu210608@gmail.com (Chenchen), https://7thparkk.github.io/
Lenny Primak <lenny@flowlogix.com>
Andrea Cosentino