7.4
CVE-2026-86247
- EPSS 0.18%
- Veröffentlicht 23.09.2026 12:31:53
- Zuletzt bearbeitet 06.10.2026 13:46:49
- Erkennungen
Apache Tomcat Native: Client certificate requirements can be down-graded
Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Native Version >= 1.3.0 < 1.3.9
Apache ≫ Tomcat Native Version >= 2.0.0 < 2.0.16
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.066 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-366 Race Condition within a Thread
If two threads of execution use a resource simultaneously, there exists the possibility that resources may be used while invalid, in turn making the state of execution undefined.
https://lists.apache.org/thread/obsson6zhvfg0wsp2bx602l61ltj87r1
http://www.openwall.com/lists/oss-security/2026/09/23/33