CVE-2022-40664

CRITICAL

Apache Shiro < 1.10.0 - Authentication Bypass via RequestDispatcher

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-40664. PoCs published by JAckLosingHeart.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2022-40664, an authentication bypass vulnerability in Apache Shiro. The exploit demonstrates how an attacker can bypass Shiro's URL-based access control by manipulating request paths and forwarding requests to protected endpoints.

Description

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

Exploits (1)

github WORKING POC 5 stars
by JAckLosingHeart · javapoc
https://github.com/JAckLosingHeart/CVE-PoC-Collection/tree/main/shiro-CVE-2022-40664

This repository contains a functional proof-of-concept for CVE-2022-40664, an authentication bypass vulnerability in Apache Shiro. The exploit demonstrates how an attacker can bypass Shiro's URL-based access control by manipulating request paths and forwarding requests to protected endpoints.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Apache Shiro (versions affected by CVE-2022-40664)
No auth needed
Prerequisites: Apache Shiro with vulnerable configuration · Access to a vulnerable endpoint
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List, Release Notes, Vendor Advisory
https://lists.apache.org/thread/loc2ktxng32xpy7lfwxto13k4lvnhjwg
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/10/12/1
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/10/12/2
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/10/13/1

Scores

CVSS v3 9.8
EPSS 0.0054
EPSS Percentile 68.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (2)
apache/shiro < 1.10.0
org.apache.shiro/shiro-core 0 - 1.10.0Maven
Published Oct 12, 2022
Tracked Since Feb 18, 2026