7.5

CVE-2026-34486

Warnung
Medienbericht

Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

04.08.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Schwachstelle

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 82.93% 0.996
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

CWE-807 Reliance on Untrusted Inputs in a Security Decision

The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
07.08.2026 12:31
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.08.2026 18:15
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.08.2026 11:00
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
30.07.2026 18:25
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
20.04.2026 16:46
https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
Vendor Advisory
Mailing List
https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat
Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat
Third Party Advisory
Mitigation
https://bugzilla.redhat.com/show_bug.cgi?id=2457027
Third Party Advisory
Issue Tracking
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36787
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36788
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36789
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36790
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36876
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36877
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36878
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36879
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:37136
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:37137
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-34486
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:38505
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:39188
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:39189
Third Party Advisory
https://socradar.io/blog/snowlight-government-chinese-campaign/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486
US Government Resource