Server Misconfiguration in Apache Shiro's Jakarta EE Module
CVE-2026-58301

5.9MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
31 August 2026

What is CVE-2026-58301?

A vulnerability exists in Apache Shiro when used with the Jakarta EE integration module. A low-privileged user can exploit this issue by crafting a malicious HTTP request, which leads the server to connect to an attacker-controlled URL. This may result in unintended data transmission to the attacker, compromising the integrity and confidentiality of the application's data. Users are advised to upgrade to version 3.0.1 or higher to mitigate this risk. Additionally, setting specific system properties can restrict connections made during form resubmissions, enhancing security further.

Affected Version(s)

Apache Shiro 2.0.0-alpha-0 <= 3.0.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

liyi.zhou@sydney.edu.au (Liyi), https://lzhou1110.github.io/
ziyue0530@gmail.com (Ziyue), https://zyy0530.github.io/
cshe0476@uni.sydney.edu.au (Strick), https://str1ckl4nd.github.io/
chng0012@uni.sydney.edu.au (Maurice), http://maurice.busystar.org/
cyu210608@gmail.com (Chenchen), https://7thparkk.github.io/
Lenny Primak <lenny@flowlogix.com>
Andrea Cosentino
.