Apache · Apache Shiro · CVE-2026-56091
**Name of the Vulnerable Software and Affected Versions**
Apache Shiro versions prior to 3.0.0
**Description**
When using the `shiro-guice` module within a web servlet context, a specially crafted HTTP request can lead to an authentication bypass. This allows an attacker to circumvent security checks and gain unauthorized access to protected resources.
**Recommendations**
Upgrade to version 3.0.0 or later.