Vulnerability record · CVE-2026-34486 · published 9 April 2026
CVE-2026-34486: Apache Tomcat EncryptInterceptor bypass exposes sensitive data
Apache · Tomcat
Apache Tomcat contains a missing encryption of sensitive data flaw: the fix for CVE-2026-29146 can be bypassed, allowing the EncryptInterceptor to be circumvented. This matters because data that operators expect to be encrypted in transit may be transmitted in the clear. Affected versions are 11.0.20, 10.1.53 and 9.0.116; fixes are in 11.0.21, 10.1.54 and 9.0.117.
Description
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is in CISA KEV with a near-maximum EPSS score and allows unauthenticated network attackers to obtain sensitive data, so it warrants immediate patching.
What it is
Apache Tomcat contains a missing encryption of sensitive data flaw: the fix for CVE-2026-29146 can be bypassed, allowing the EncryptInterceptor to be circumvented. This matters because data that operators expect to be encrypted in transit may be transmitted in the clear. Affected versions are 11.0.20, 10.1.53 and 9.0.116; fixes are in 11.0.21, 10.1.54 and 9.0.117.
Impact
An attacker who can observe or intercept the affected traffic gains access to sensitive data that the EncryptInterceptor was meant to protect, resulting in confidentiality loss. The CVSS vector shows no integrity or availability impact.
Attack surface
Reachable over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). The flaw sits in the Tomcat clustering/EncryptInterceptor path, so exposure depends on deployments that rely on that interceptor for encryption.
Exploitation
CVE-2026-34486 is listed in CISA KEV with a due date of 2026-08-07, and EPSS is 0.98616 (99.9th percentile), indicating observed exploitation activity. No ransomware campaign use is documented in the record.
What to do
- Upgrade Apache Tomcat to 11.0.21, 10.1.54 or 9.0.117 as directed by the vendor advisory.
- Apply the Red Hat errata (RHSA-2026:36787 through RHSA-2026:39189) for affected JBoss Web Server and Enterprise Linux packages.
- Follow CISA BOD 26-04 guidance, including evaluating internet exposure of each Tomcat asset and applying the required action by the KEV due date.
- If patching cannot be completed immediately, discontinue use of the affected component or isolate the clustering traffic until the fix is applied.
- Verify that EncryptInterceptor is actually enforcing encryption after upgrade rather than assuming the configuration is effective.
Detection
- Monitor for anomalous or cleartext traffic on Tomcat cluster/interceptor ports that should be encrypted.
- Review Tomcat and JBoss Web Server versions in inventory against the fixed releases 11.0.21, 10.1.54 and 9.0.117.
- Hunt for signs of interception or credential/data capture on segments carrying Tomcat cluster traffic.
- Track KEV and vendor advisory updates for this CVE and confirm remediation status of exposed instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-34486 to the Known Exploited Vulnerabilities catalog on 4 August 2026 as "Apache Tomcat Missing Encryption of Sensitive Data Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 7 August 2026.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-34486 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-34486), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.