cbcvebase.
CVE-2026-49268
published 2026-06-17

CVE-2026-49268: Apache Shiro: LDAP DN Injection in DefaultLdapRealm A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in…

high8.8CVSS 4.0
AVNACLATNPRNUINVCLVIHVANSCNSINSANSPAUYRARELURed
EPSS
0.49%
39.0th percentile
Apache Shiro: LDAP DN Injection in DefaultLdapRealm A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users. This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issue.

Affected

2 ranges
VendorProductVersion rangeFixed in
apache_software_foundationapache_shiro<= 2.2.0
apache_software_foundationapache_shiro3.0.0-alpha-0 – 3.0.0-alpha-1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.