PT-2026-50410 · Apache · Apache Shiro

·

CVE-2026-49268

·

Published

2026-06-17

·

Updated

2026-07-21

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Shiro versions prior to 2.2.1 Apache Shiro versions prior to 3.0.0-alpha-2
Description A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction within the DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without escaping RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially leading to authentication bypass or user impersonation.
Recommendations Upgrade to version 2.2.1 or later. Upgrade to version 3.0.0-alpha-2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08941
CLEANSTART-2026-CQ01177
CVE-2026-49268
GHSA-X96M-RH44-VGV8

Affected Products

Apache Shiro