HIGH

CVE-2026-34486

Apache Tomcat 2026-04-09 CVSS v3.1
CVSS
7.5
KEV

Description

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Summary dbcve.org

This is a Missing Encryption of Sensitive Data vulnerability in Apache Tomcat's EncryptInterceptor. The fix for the related CVE-2026-29146 introduced a bypass that allows sensitive data to be transmitted without proper encryption in clustered Tomcat deployments using the EncryptInterceptor.

Mitigation

Upgrade Apache Tomcat to version 11.0.21, 10.1.54, or 9.0.117 to obtain the patched EncryptInterceptor implementation.

Weakness (CWE)

CWE-311
CWE-807

EPSS Score

98.62%
Probability of exploitation in next 30 days
99.9th percentile

References

https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly Mailing List, Vendor Advisory https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat Third Party Advisory https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat Mitigation, Third Party Advisory https://access.redhat.com/errata/RHSA-2026:36787 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:36788 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:36789 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:36790 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:36876 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:36877 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:36878 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:36879 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:37136 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:37137 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:38505 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:39188 Third Party Advisory https://access.redhat.com/errata/RHSA-2026:39189 Third Party Advisory https://access.redhat.com/security/cve/CVE-2026-34486 Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2457027 Issue Tracking, Third Party Advisory https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json Third Party Advisory https://socradar.io/blog/snowlight-government-chinese-campaign/ Third Party Advisory https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE