---
cve: "CVE-2026-48589"
severity: "LOW"
cvss: 3.1
epss: "35%"
vendor: "Apache Software Foundation"
kev: false
exploited: false
published: "2026-05-25 21:16:35"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T12:34:35+02:00"
---

# CVE-2026-48589

> 3.1 LOW

## Beschreibung

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login.
In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module.
This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.

## Referenzen

- <https://shiro.apache.org/security-reports.html#cve_2026_48589>
- <http://www.openwall.com/lists/oss-security/2026/05/25/9>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-48589) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
