CVE-2026-34486
Published Apr 9, 2026
Last updated 8 days ago
AI description
CVE-2026-34486 is a vulnerability found in Apache Tomcat Tribes, specifically within the `EncryptInterceptor` component responsible for decrypting cluster messages. This issue stems from a regression introduced during a fix for a prior vulnerability, CVE-2026-29146. The regression causes decryption failures to "fail open" rather than "fail closed," meaning that when decryption fails, the original unencrypted or malformed message is still forwarded for processing, bypassing the intended encryption protection. This bypass allows attacker-supplied bytes to reach Tomcat's Java deserialization code path, which utilizes `ObjectInputStream.readObject()` without an `ObjectInputFilter` in the affected flow. Consequently, untrusted serialized objects can be loaded and instantiated. The vulnerability is also described as a "Missing Encryption of Sensitive Data" flaw, enabling the bypass of the `EncryptInterceptor` and potentially exposing sensitive data that should have been encrypted.
- Description
- Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- tomcat, jboss_web_server, enterprise_linux, enterprise_linux_els, enterprise_linux_eus, enterprise_linux_tus, enterprise_linux_update_services_for_sap_solutions
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Exploit added on
- Aug 4, 2026
- Exploit action due
- Aug 7, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Hype score
- Not currently trending
Tomcat's own patch didn't close the hole. CVE-2026-34486 (CVSS 7.5) bypasses EncryptInterceptor because the fix for CVE-2026-29146 was incomplete. Real fix shipped in April. CISA's KEV Aug 4, FCEB deadline today. Two unrelated threat actors already exploited it. Verifying fixes,
@beuchelt
7 Aug 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apache TomcatのCVE-2026-34486(機微データにおける暗号化欠如)は同製品のCVE-2025-24813(partial PUTにおけるパス同等性の不備)と連鎖可能。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆
@__kokumoto
6 Aug 2026
810 Impressions
1 Retweet
4 Likes
2 Bookmarks
0 Replies
0 Quotes
🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz 🎯 Zafiyet Bilgisi Ürün: #Apache #Tomcat #Zafiyet: Hassas Verilerin Şifrelenmemesi (Missing Encryption of Sensitive Data) CVE: CVE-2026-34486 Zafiyet Türü: Missing Encrypti
@rahmid3mir
6 Aug 2026
77 Impressions
3 Retweets
11 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-of-the-Day: CVE-2026-34486 — Apache Tomcat cluster encryption bypass CVSS: 7.5 | EPSS: 0.01 A bug bypasses Tomcat's EncryptInterceptor — the pre-shared-key encryption between cluster nodes — leaving node-to-node traffic unencrypted. #CVE #infosec https://t.co/sn
@YourDailyCVE
6 Aug 2026
8 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-9198 | IBM Langflow CVSS 9.8 pre-auth RCE 2 HTTP requests. No creds. Full Python exec. CISA KEV deadline: Aug 7. DeepSeek AI hit 460+ Tomcat endpoints (CVE-2026-34486). Fix: Langflow 1.10.1 https://t.co/UgUFOfkLAX #CVE20269198 #PatchNow
@DecryptionDigst
6 Aug 2026
56 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
CISA added CVE-2026-9198, CVE-2026-34486 and CVE-2026-18556 to the KEV catalog. CVE-2026-9198 lets unauthenticated attackers chain Langflow APIs for code execution. CVE-2026-34486 bypasses Apache Tomcat EncryptInterceptor encryption. N-central CVE-2026-18556 enables auth bypass;
@WorldCyberNewsX
5 Aug 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が、既知の悪用された脆弱性カタログに、LangflowのCVE-2026-9198、N-able N-centralのCVE-2026-18556、Apache TomcatのCVE-2026-34486を追加。対処期限は3日後の8/7。ランサムウ
@__kokumoto
4 Aug 2026
774 Impressions
0 Retweets
3 Likes
3 Bookmarks
1 Reply
0 Quotes
🛡️We added IBM Langflow vulnerability CVE-2026-9198, N-able N-central vulnerability CVE-2026-18556 & Apache Tomcat vulnerability CVE-2026-34486 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity
@CISACyber
4 Aug 2026
9071 Impressions
14 Retweets
38 Likes
8 Bookmarks
5 Replies
1 Quote
Unauthenticated RCE in Apache Tomcat (CVE-2026-34486) https://t.co/erOSunmEpT
@termireum
7 Jun 2026
479 Impressions
4 Retweets
11 Likes
6 Bookmarks
0 Replies
0 Quotes
BREAKING: Apache Tomcat EncryptInterceptor encryption bypass in CVE-2026-34486 hits 11.0.20, 10.1.53, 9.0.116, PoC dropped April 15 2026, upgrade to 11.0.21, 10.1.54 or 9.0.117. https://t.co/QW7w1DoU1r
@threatcluster
28 May 2026
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-34486: PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github. Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak.
@lyrie_ai
12 May 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:tomcat:9.0.116:*:*:*:*:*:*:*",
"matchCriteriaId": "CC160F23-A9D6-42DA-92E6-886B1B1F48A6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:tomcat:10.1.53:*:*:*:*:*:*:*",
"matchCriteriaId": "0E7A0CE9-EBDF-4305-9C06-E7D4521AF422",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:tomcat:11.0.20:*:*:*:*:*:*:*",
"matchCriteriaId": "64BAAE4D-2355-43D8-83E5-01CA71D5DC0B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:jboss_web_server:7.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F764C52A-4533-4C39-A5A2-A5E1FE20960C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "7F6FB57C-2BC7-487C-96DD-132683AEB35D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*",
"matchCriteriaId": "D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_els:7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "0460F769-D90A-4446-AC00-24F66BDBF526",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:10.0:*:*:*:*:*:*:*",
"matchCriteriaId": "34990D09-125F-48CA-B85E-9D9F0EB4BC07",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_tus:8.8:*:*:*:*:*:*:*",
"matchCriteriaId": "22D28543-C7C5-46B0-B909-20435AF7A501",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*",
"matchCriteriaId": "01ED4F33-EBE7-4C04-8312-3DA580EFFB68",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*",
"matchCriteriaId": "1FD9BF0E-7ACF-4A83-B754-6E3979ED903F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.4:*:*:*:*:*:*:*",
"matchCriteriaId": "18B7F648-9A31-4EE5-A215-C860616A4AB7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.6:*:*:*:*:*:*:*",
"matchCriteriaId": "554AA8CA-A930-4788-B052-497E09D48381",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]