CVE-2026-34486

Published Apr 9, 2026

Last updated 8 days ago

Exploit knownCVSS high 7.5
Apache Tomcat
web application
Zero-day

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-34486 is a vulnerability found in Apache Tomcat Tribes, specifically within the `EncryptInterceptor` component responsible for decrypting cluster messages. This issue stems from a regression introduced during a fix for a prior vulnerability, CVE-2026-29146. The regression causes decryption failures to "fail open" rather than "fail closed," meaning that when decryption fails, the original unencrypted or malformed message is still forwarded for processing, bypassing the intended encryption protection. This bypass allows attacker-supplied bytes to reach Tomcat's Java deserialization code path, which utilizes `ObjectInputStream.readObject()` without an `ObjectInputFilter` in the affected flow. Consequently, untrusted serialized objects can be loaded and instantiated. The vulnerability is also described as a "Missing Encryption of Sensitive Data" flaw, enabling the bypass of the `EncryptInterceptor` and potentially exposing sensitive data that should have been encrypted.

Description
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Source
security@apache.org
NVD status
Analyzed
Products
tomcat, jboss_web_server, enterprise_linux, enterprise_linux_els, enterprise_linux_eus, enterprise_linux_tus, enterprise_linux_update_services_for_sap_solutions

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Exploit added on
Aug 4, 2026
Exploit action due
Aug 7, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

security@apache.org
CWE-311
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-807

Social media

Hype score
Not currently trending
  1. Tomcat's own patch didn't close the hole. CVE-2026-34486 (CVSS 7.5) bypasses EncryptInterceptor because the fix for CVE-2026-29146 was incomplete. Real fix shipped in April. CISA's KEV Aug 4, FCEB deadline today. Two unrelated threat actors already exploited it. Verifying fixes,

    @beuchelt

    7 Aug 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Apache TomcatのCVE-2026-34486(機微データにおける暗号化欠如)は同製品のCVE-2025-24813(partial PUTにおけるパス同等性の不備)と連鎖可能。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆

    @__kokumoto

    6 Aug 2026

    810 Impressions

    1 Retweet

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  3. 🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz 🎯 Zafiyet Bilgisi Ürün: #Apache #Tomcat #Zafiyet: Hassas Verilerin Şifrelenmemesi (Missing Encryption of Sensitive Data) CVE: CVE-2026-34486 Zafiyet Türü: Missing Encrypti

    @rahmid3mir

    6 Aug 2026

    77 Impressions

    3 Retweets

    11 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-of-the-Day: CVE-2026-34486 — Apache Tomcat cluster encryption bypass CVSS: 7.5 | EPSS: 0.01 A bug bypasses Tomcat's EncryptInterceptor — the pre-shared-key encryption between cluster nodes — leaving node-to-node traffic unencrypted. #CVE #infosec https://t.co/sn

    @YourDailyCVE

    6 Aug 2026

    8 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  5. CVE-2026-9198 | IBM Langflow CVSS 9.8 pre-auth RCE 2 HTTP requests. No creds. Full Python exec. CISA KEV deadline: Aug 7. DeepSeek AI hit 460+ Tomcat endpoints (CVE-2026-34486). Fix: Langflow 1.10.1 https://t.co/UgUFOfkLAX #CVE20269198 #PatchNow

    @DecryptionDigst

    6 Aug 2026

    56 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. CISA added CVE-2026-9198, CVE-2026-34486 and CVE-2026-18556 to the KEV catalog. CVE-2026-9198 lets unauthenticated attackers chain Langflow APIs for code execution. CVE-2026-34486 bypasses Apache Tomcat EncryptInterceptor encryption. N-central CVE-2026-18556 enables auth bypass;

    @WorldCyberNewsX

    5 Aug 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が、既知の悪用された脆弱性カタログに、LangflowのCVE-2026-9198、N-able N-centralのCVE-2026-18556、Apache TomcatのCVE-2026-34486を追加。対処期限は3日後の8/7。ランサムウ

    @__kokumoto

    4 Aug 2026

    774 Impressions

    0 Retweets

    3 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  8. 🛡️We added IBM Langflow vulnerability CVE-2026-9198, N-able N-central vulnerability CVE-2026-18556 & Apache Tomcat vulnerability CVE-2026-34486 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity

    @CISACyber

    4 Aug 2026

    9071 Impressions

    14 Retweets

    38 Likes

    8 Bookmarks

    5 Replies

    1 Quote

  9. Unauthenticated RCE in Apache Tomcat (CVE-2026-34486) https://t.co/erOSunmEpT

    @termireum

    7 Jun 2026

    479 Impressions

    4 Retweets

    11 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  10. BREAKING: Apache Tomcat EncryptInterceptor encryption bypass in CVE-2026-34486 hits 11.0.20, 10.1.53, 9.0.116, PoC dropped April 15 2026, upgrade to 11.0.21, 10.1.54 or 9.0.117. https://t.co/QW7w1DoU1r

    @threatcluster

    28 May 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2026-34486: PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github. Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak.

    @lyrie_ai

    12 May 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations