DNA View

CVE-2026-23901

Low
Low Medium High Critical
2.5
CVSS Score
Published: Feb 10, 2026
Last Modified: Feb 12, 2026

Vulnerability Description

Observable Timing Discrepancy vulnerability in Apache Shiro.

This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7.

Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue.

Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough,
that a brute-force attack may be able to tell, by timing the requests only, determine if
the request failed because of a non-existent user vs. wrong password.

The most likely attack vector is a local attack only.
Shiro security model  https://shiro.apache.org/security-model.html#username_enumeration  discusses this as well.

Typically, brute force attack can be mitigated at the infrastructure level.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
L
Attack Complexity
H
Privileges Required
L
User Interaction
N
Scope
U
Confidentiality
L
Integrity
N
Availability
N

Known Affected Software

31 configuration(s) from 1 vendor(s)

shiro
Version:
1.9.0
CPE:
cpe:2.3:a:apache:shiro:1.9.0:*:*:*:*:*:*:*
shiro
Version:
1.12.0
CPE:
cpe:2.3:a:apache:shiro:1.12.0:*:*:*:*:*:*:*
shiro
Version:
1.9.1
CPE:
cpe:2.3:a:apache:shiro:1.9.1:*:*:*:*:*:*:*
shiro
Version:
1.2.5
CPE:
cpe:2.3:a:apache:shiro:1.2.5:*:*:*:*:*:*:*
shiro
Version:
1.4.2
CPE:
cpe:2.3:a:apache:shiro:1.4.2:*:*:*:*:*:*:*
shiro
Version:
1.2.2
CPE:
cpe:2.3:a:apache:shiro:1.2.2:*:*:*:*:*:*:*
shiro
Version:
1.2.6
CPE:
cpe:2.3:a:apache:shiro:1.2.6:*:*:*:*:*:*:*
shiro
Version:
1.3.0
CPE:
cpe:2.3:a:apache:shiro:1.3.0:*:*:*:*:*:*:*
shiro
Version:
1.7.0
CPE:
cpe:2.3:a:apache:shiro:1.7.0:*:*:*:*:*:*:*
shiro
Version:
1.2.4
CPE:
cpe:2.3:a:apache:shiro:1.2.4:*:*:*:*:*:*:*
shiro
Version:
1.5.0
CPE:
cpe:2.3:a:apache:shiro:1.5.0:*:*:*:*:*:*:*
shiro
Version:
1.5.1
CPE:
cpe:2.3:a:apache:shiro:1.5.1:*:*:*:*:*:*:*
shiro
Version:
1.6.0
CPE:
cpe:2.3:a:apache:shiro:1.6.0:*:*:*:*:*:*:*
shiro
Version:
1.2.1
CPE:
cpe:2.3:a:apache:shiro:1.2.1:*:*:*:*:*:*:*
shiro
Version:
1.3.2
CPE:
cpe:2.3:a:apache:shiro:1.3.2:*:*:*:*:*:*:*
shiro
Version:
1.0.0
CPE:
cpe:2.3:a:apache:shiro:1.0.0:*:*:*:*:*:*:*
shiro
Version:
1.8.0
CPE:
cpe:2.3:a:apache:shiro:1.8.0:*:*:*:*:*:*:*
shiro
Version:
1.4.0
CPE:
cpe:2.3:a:apache:shiro:1.4.0:-:*:*:*:*:*:*
shiro
Version:
1.2.0
CPE:
cpe:2.3:a:apache:shiro:1.2.0:*:*:*:*:*:*:*
shiro
Version:
1.2.3
CPE:
cpe:2.3:a:apache:shiro:1.2.3:*:*:*:*:*:*:*
shiro
Version:
1.10.0
CPE:
cpe:2.3:a:apache:shiro:1.10.0:*:*:*:*:*:*:*
shiro
Version:
2.0.0
CPE:
cpe:2.3:a:apache:shiro:2.0.0:alpha3:*:*:*:*:*:*
shiro
Version:
1.13.0
CPE:
cpe:2.3:a:apache:shiro:1.13.0:*:*:*:*:*:*:*
shiro
Version:
1.5.3
CPE:
cpe:2.3:a:apache:shiro:1.5.3:*:*:*:*:*:*:*
shiro
Version:
1.4.1
CPE:
cpe:2.3:a:apache:shiro:1.4.1:*:*:*:*:*:*:*
shiro
Version:
1.10.1
CPE:
cpe:2.3:a:apache:shiro:1.10.1:*:*:*:*:*:*:*
shiro
Version:
1.7.1
CPE:
cpe:2.3:a:apache:shiro:1.7.1:*:*:*:*:*:*:*
shiro
Version:
1.11.0
CPE:
cpe:2.3:a:apache:shiro:1.11.0:*:*:*:*:*:*:*
shiro
Version:
1.1.0
CPE:
cpe:2.3:a:apache:shiro:1.1.0:*:*:*:*:*:*:*
shiro
Version:
1.5.2
CPE:
cpe:2.3:a:apache:shiro:1.5.2:*:*:*:*:*:*:*
shiro
Version:
1.3.1
CPE:
cpe:2.3:a:apache:shiro:1.3.1:*:*:*:*:*:*:*
This vulnerability affects 31 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

1 patch available from vendors

View All Patches
Oracle

CPUAPR2026

Oracle Critical Patch Update Advisory - April 2026

Severity
Critical
Released
Apr 21, 2026
Restart Required
Security Update

Severity Details

2.5
out of 10.0
Low

Weakness Type (CWE)

CWE-208

Observable Timing Discrepancy

Description
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful…
Typical Severity
Medium
Abstraction Level
Base

Key Information

Published Date
February 10, 2026