Apache · Apache Shiro · CVE-2026-56130
**Name of the Vulnerable Software and Affected Versions**
Apache Shiro versions 1.2.4 through 2.x
Apache Shiro version 3.0.0-alpha-1
**Description**
The server does not verify the age of the "Remember me" cookie when the RememberMe functionality is enabled. This allows an attacker to intercept a valid cookie and reuse it indefinitely, bypassing the configured expiration time.
**Recommendations**
Upgrade to version 3.0.0 or later.
As a temporary mitigation, disable the RememberMe functionality.