Junglewise Threat Intelligence

CVE-2026-56130: Apache Shiro authentication bypass via RememberMe cookie replay

CVE-2026-56130 · Severity: info · CVSS 2 · Published 2026-06-25

Technologies: Apache Shiro. Vendors: Apache.

Executive brief

Apache Shiro, a security framework for Java applications, contains a flaw in its 'Remember Me' login feature. An attacker who intercepts a user's login cookie can reuse it to gain access to the application indefinitely, even after the cookie was supposed to expire. This could lead to unauthorized account access if a user's session information is compromised.

Technical details

A vulnerability exists in Apache Shiro's RememberMe functionality where the server fails to validate the age of the 'Remember Me' cookie. This is classified as an authentication bypass by capture-replay (CWE-294). An attacker who successfully intercepts a valid 'Remember Me' cookie can replay it to the server to maintain an authenticated session indefinitely, bypassing configured expiration policies. The issue affects versions 1.2.4 through 2.x and 3.0.0-alpha-1. Users are advised to upgrade to version 3.0.0 or later to ensure server-side age verification is enforced.

Affected products

  • Apache Shiro 1.2.4 through 2.x, 3.0.0-alpha-1

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References