HIGH
CVE-2026-34486
CVSS
7.5
KEV
Description
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Summary dbcve.org
This is a Missing Encryption of Sensitive Data vulnerability in Apache Tomcat's EncryptInterceptor. The fix for the related CVE-2026-29146 introduced a bypass that allows sensitive data to be transmitted without proper encryption in clustered Tomcat deployments using the EncryptInterceptor.
Mitigation
Upgrade Apache Tomcat to version 11.0.21, 10.1.54, or 9.0.117 to obtain the patched EncryptInterceptor implementation.
Weakness (CWE)
CWE-311
CWE-807
EPSS Score
98.62%
Probability of exploitation in next 30 days
99.9th percentile
References
https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
Mailing List, Vendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat
Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat
Mitigation, Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36787
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36788
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36789
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36790
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36876
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36877
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36878
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36879
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:37136
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:37137
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:38505
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:39188
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:39189
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-34486
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2457027
Issue Tracking, Third Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json
Third Party Advisory
https://socradar.io/blog/snowlight-government-chinese-campaign/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.