← Vulnerability feed

Vulnerability record · CVE-2026-34486 · published 9 April 2026

CVE-2026-34486: Apache Tomcat EncryptInterceptor bypass exposes sensitive data

Apache · Tomcat

Apache Tomcat contains a missing encryption of sensitive data flaw: the fix for CVE-2026-29146 can be bypassed, allowing the EncryptInterceptor to be circumvented. This matters because data that operators expect to be encrypted in transit may be transmitted in the clear. Affected versions are 11.0.20, 10.1.53 and 9.0.116; fixes are in 11.0.21, 10.1.54 and 9.0.117.

7.5 CVSS 3.1 High CISA KEV since 4 Aug 2026 EPSS 6.6% · top 6.4% CWE-311 · Missing encryptionCWE-807 · CWE-807
7.5CVSS 3.1 base score
6.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
21References
21 Sep 2026Last modified by NVD

Description

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw is in CISA KEV with a near-maximum EPSS score and allows unauthenticated network attackers to obtain sensitive data, so it warrants immediate patching.

What it is

Apache Tomcat contains a missing encryption of sensitive data flaw: the fix for CVE-2026-29146 can be bypassed, allowing the EncryptInterceptor to be circumvented. This matters because data that operators expect to be encrypted in transit may be transmitted in the clear. Affected versions are 11.0.20, 10.1.53 and 9.0.116; fixes are in 11.0.21, 10.1.54 and 9.0.117.

Impact

An attacker who can observe or intercept the affected traffic gains access to sensitive data that the EncryptInterceptor was meant to protect, resulting in confidentiality loss. The CVSS vector shows no integrity or availability impact.

Attack surface

Reachable over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). The flaw sits in the Tomcat clustering/EncryptInterceptor path, so exposure depends on deployments that rely on that interceptor for encryption.

Exploitation

CVE-2026-34486 is listed in CISA KEV with a due date of 2026-08-07, and EPSS is 0.98616 (99.9th percentile), indicating observed exploitation activity. No ransomware campaign use is documented in the record.

What to do

  • Upgrade Apache Tomcat to 11.0.21, 10.1.54 or 9.0.117 as directed by the vendor advisory.
  • Apply the Red Hat errata (RHSA-2026:36787 through RHSA-2026:39189) for affected JBoss Web Server and Enterprise Linux packages.
  • Follow CISA BOD 26-04 guidance, including evaluating internet exposure of each Tomcat asset and applying the required action by the KEV due date.
  • If patching cannot be completed immediately, discontinue use of the affected component or isolate the clustering traffic until the fix is applied.
  • Verify that EncryptInterceptor is actually enforcing encryption after upgrade rather than assuming the configuration is effective.

Detection

  • Monitor for anomalous or cleartext traffic on Tomcat cluster/interceptor ports that should be encrypted.
  • Review Tomcat and JBoss Web Server versions in inventory against the fixed releases 11.0.21, 10.1.54 and 9.0.117.
  • Hunt for signs of interception or credential/data capture on segments carrying Tomcat cluster traffic.
  • Track KEV and vendor advisory updates for this CVE and confirm remediation status of exposed instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-34486 to the Known Exploited Vulnerabilities catalog on 4 August 2026 as "Apache Tomcat Missing Encryption of Sensitive Data Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 7 August 2026.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly Mailing ListVendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat MitigationThird Party Advisory
https://access.redhat.com/errata/RHSA-2026:36787 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36788 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36789 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36790 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36876 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36877 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36878 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36879 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:37136 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:37137 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:38505 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:39188 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:39189 Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-34486 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2457027 Issue TrackingThird Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json Third Party Advisory
https://socradar.io/blog/snowlight-government-chinese-campaign/ Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486 US Government Resource

Track CVE-2026-34486 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2018-14667RichFaces Framework EL injection enables unauthenticated remote code executionRichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language injection through the UserResource resource. A remote, unauthenticated att…KEVEPSS 74%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2026-34486), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.