
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23901 is an Observable Timing Discrepancy vulnerability (CWE-208) in Apache Shiro that enables username enumeration via brute-force timing analysis. It affects all Apache Shiro versions in the 1.x series and 2.x versions prior to 2.0.7. The vulnerability was disclosed on February 8–10, 2026, with the CVE published on February 10, 2026. It carries a CVSS v3.1 base score of 2.5 (Low) and a CVSS v4.0 base score of 1.0 (Low) (GitHub Advisory, Red Hat Bugzilla).
The root cause is that Apache Shiro's authentication code paths differ measurably between attempts for non-existent users versus existing users with incorrect passwords (CWE-208: Observable Timing Discrepancy). An attacker with local access and low privileges can time repeated authentication requests to statistically distinguish between "user not found" and "wrong password" responses, effectively enumerating valid usernames. Exploitation requires high attack complexity, local access, and some level of privileges, making it a constrained but real information-disclosure risk. The vulnerability was discovered by security researchers 4ra1n and Y4tacker, with remediation developed by lprimak (oss-security, GitHub Advisory).
Successful exploitation allows an attacker to enumerate valid usernames in an Apache Shiro-protected application by measuring response time differences during authentication attempts. The impact is limited to low confidentiality disclosure — no integrity or availability impact is present. Enumerated usernames can then be leveraged in targeted credential-stuffing or password-spraying attacks, incrementally weakening the overall security posture of the affected application (GitHub Advisory, Red Hat Bugzilla).
time.perf_counter() or a custom script).The primary remediation is to upgrade Apache Shiro to version 2.0.7 or later, which equalizes the authentication code paths to eliminate the timing discrepancy (GitHub Advisory, oss-security). As infrastructure-level mitigations, implement rate limiting and account lockout policies on authentication endpoints to impede brute-force timing attacks. Deploying an intrusion detection system capable of identifying high-frequency authentication failures and normalizing authentication response times at the application or proxy layer can further reduce risk.
The vulnerability was disclosed via the Apache security mailing list and the oss-security list on February 8, 2026, with the CVE published on February 10, 2026. Red Hat tracked the issue via Bugzilla (Bug 2438436) and assigned it a low severity rating. Community reaction has been muted given the low CVSS score, local-only attack vector, and absence of public exploits; the Apache Shiro security model documentation was cited as already acknowledging username enumeration as a known risk (oss-security, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."