- Description
- Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
- Source
- security@apache.org
- NVD status
- Modified
- Products
- tomcat
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- security@apache.org
- CWE-311
- Hype score
- Not currently trending
Unauthenticated RCE in Apache Tomcat (CVE-2026-34486) https://t.co/erOSunmEpT
@termireum
7 Jun 2026
479 Impressions
4 Retweets
11 Likes
6 Bookmarks
0 Replies
0 Quotes
BREAKING: Apache Tomcat EncryptInterceptor encryption bypass in CVE-2026-34486 hits 11.0.20, 10.1.53, 9.0.116, PoC dropped April 15 2026, upgrade to 11.0.21, 10.1.54 or 9.0.117. https://t.co/QW7w1DoU1r
@threatcluster
28 May 2026
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-34486: PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github. Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak.
@lyrie_ai
12 May 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:tomcat:9.0.116:*:*:*:*:*:*:*",
"matchCriteriaId": "CC160F23-A9D6-42DA-92E6-886B1B1F48A6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:tomcat:10.1.53:*:*:*:*:*:*:*",
"matchCriteriaId": "0E7A0CE9-EBDF-4305-9C06-E7D4521AF422",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:tomcat:11.0.20:*:*:*:*:*:*:*",
"matchCriteriaId": "64BAAE4D-2355-43D8-83E5-01CA71D5DC0B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]