CVE-2026-48589
MEDIUMApache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow
Title source: cnaDescription
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://shiro.apache.org/security-reports.html#cve_2026_48589
Scores
CVSS v3
5.4
EPSS
0.0035
EPSS Percentile
26.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (4)
apache/shiro
3.0.0 alpha1
apache/shiro
2.0.0 - 2.2.1
Apache Software Foundation/Apache Shiro
2.0.0-alpha-0 - 2.2.0
Apache Software Foundation/Apache Shiro
3.0.0-alpha-0 - 3.0.0-alpha-1
Published
May 25, 2026
Tracked Since
May 26, 2026