CVE-2026-34486

Aliases:GHSA-69r9-qgr7-g2wjBIT-tomcat-2026-34486UBUNTU-CVE-2026-34486
Analyzed
Published: 09 Apr 2026, 19:35
Last modified:10 Aug 2026, 12:05

Vulnerability Summary

Overall Risk (default)
medium
47/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
82.93% CRITICAL
83% probability +67.10%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Apr 2026, 19:35
Published
Vulnerability first disclosed
04 Aug 2026, 00:00
Added to CISA KEV
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
07 Aug 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
10 Aug 2026, 12:05
Last Modified
Vulnerability information updated

Description

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 82.93% Percentile: 100%

Techniques & Countermeasures

  • CWE-311Missing Encryption of Sensitive Data

    The product does not encrypt sensitive or critical information before storage or transmission.

  • CWE-807Reliance on Untrusted Inputs in a Security Decision

    The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

Affected Systems

  • apache software foundationapache tomcat

    11.0.20 | 10.1.53 | 9.0.116

  • apachetomcat

    9.0.116 | 10.1.53 | 11.0.20

  • ubuntutomcat8

    all

  • org.apache.tomcattomcat

    ≥ 11.0.20, < 11.0.21 | ≥ 10.1.53, < 10.1.54 | ≥ 9.0.116, < 9.0.117

  • org.apache.tomcattomcat-catalina

    ≥ 11.0.20, < 11.0.21 | ≥ 10.1.53, < 10.1.54 | ≥ 9.0.116, < 9.0.117

  • org.apache.tomcattomcat-tribes

    ≥ 11.0.20, < 11.0.21 | ≥ 10.1.53, < 10.1.54 | ≥ 9.0.116, < 9.0.117

  • org.apache.tomcat.embedtomcat-embed-core

    ≥ 11.0.20, < 11.0.21 | ≥ 10.1.53, < 10.1.54 | ≥ 9.0.116, < 9.0.117

  • redhatenterprise_linux

    8.0 | 9.0 | 10.0

  • redhatenterprise_linux_els

    7.0

  • redhatenterprise_linux_eus

    10.0

  • redhatenterprise_linux_tus

    8.8

  • redhatenterprise_linux_update_services_for_sap_solutions

    8.8 | 9.2 | 9.4 | 9.6

  • redhatjboss_web_server

    7.0.0

References (33)