CVE-2026-56130 Details
Description
"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expiration time has passed. This issue affects all Apache Shiro versions from 1.2.4 through 2.x, and 3.0.0-alpha-1, only when RememberMe functionality is enabled. Upgrade to version 3.0.0 or later, which fixes the issue.
A vulnerability exists in Apache Shiro's handling of "Remember me" cookies, specifically in versions 1.2.4 prior to 2.0.0 and 3.0.0-alpha-0 prior to 3.0.0-alpha-1, when the RememberMe feature is enabled. The issue arises because the server does not verify the age of the "Remember me" cookies, allowing an attacker to intercept a valid cookie and reuse it indefinitely, even after its intended expiration date. This could lead to unauthorized access by bypassing the cookie's expiration mechanism.
Users are advised to upgrade to Apache Shiro version 3.0.0 or later, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/24/8 | CVE | |
| https://lists.apache.org/thread/9k9b3bmlq516ylvf7cdp3dlrtdtmxbmo | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache Shiro | >= 1.2.4, <= 2.99.99 (semver) >= 3.0.0-alpha-0, <= 3.0.0-alpha-1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | CVE Modified | CVE |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion