Apache disclosed CVE-2026-56091, an authentication bypass vulnerability in the Apache Shiro shiro-guice module when deployed in a web servlet context. The flaw allows a specially crafted HTTP request to bypass authentication checks, creating a risk that unauthenticated users could reach protected application functionality. Apache described the issue as similar to CVE-2020-1957, but affecting shiro-guice rather than shiro-spring.
The vulnerability affects all Apache Shiro 2.x releases and 3.0.0-alpha-0 through 3.0.0-alpha-1 for the org.apache.shiro:shiro-guice component under the specified deployment conditions. Apache said the issue is remediated in Apache Shiro 3.0.0 and later and advised users to upgrade. The vulnerability was credited to LocalHost for discovery, with Lenny Primak credited for developing the fix.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
In the disclosure, Apache stated that upgrading to Apache Shiro 3.0.0 or later remediates CVE-2026-56091. The issue was credited to LocalHost for discovery and Lenny Primak for remediation development.
Apache disclosed CVE-2026-56091, an authentication bypass vulnerability in the Apache Shiro shiro-guice module when used in a web servlet context. The flaw can be triggered by a specially crafted HTTP request and affects all 2.x releases as well as 3.0.0-alpha-0 through 3.0.0-alpha-1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcelists.apache.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.