CVE-2026-49268
published 2026-06-17CVE-2026-49268: Apache Shiro: LDAP DN Injection in DefaultLdapRealm A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in…
high8.8CVSS 4.0
AVNACLATNPRNUINVCLVIHVANSCNSINSANSPAUYRARELURed
EPSS
0.49%
39.0th percentile
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users.
This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm
Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_shiro | <= 2.2.0 | — |
| apache_software_foundation | apache_shiro | 3.0.0-alpha-0 – 3.0.0-alpha-1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Shiro up to 2.2.0/3.0.0-alpha-1 DefaultLdapRealm ldap injection
vuldb·2026-06-17
CVE-2026-49268 [CRITICAL] Apache Shiro up to 2.2.0/3.0.0-alpha-1 DefaultLdapRealm ldap injection
A vulnerability labeled as critical has been found in Apache Shiro up to 2.2.0/3.0.0-alpha-1. This impacts the function DefaultLdapRealm. The manipulation results in ldap injection.
This vulnerability was named CVE-2026-49268. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
GHSA
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
ghsa·2026-06-17
CVE-2026-49268 [HIGH] CWE-90 Apache Shiro: LDAP DN Injection in DefaultLdapRealm
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users.
This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm
Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issue.
CVEList
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
cvelistv5·2026-06-17·CVSS 8.8
CVE-2026-49268 [HIGH] CWE-90 Apache Shiro: LDAP DN Injection in DefaultLdapRealm
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users.
This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm
Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-17
Published