Improper Authorization Vulnerability in Apache Tomcat
CVE-2026-55956

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 June 2026

What is CVE-2026-55956?

An improper authorization vulnerability exists in Apache Tomcat that causes security constraints for the default servlet to be ignored. This flaw affects multiple versions, potentially allowing unauthorized access to web resources. Users are encouraged to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.22

Apache Tomcat 10.1.0-M1 <= 10.1.55

Apache Tomcat 9.0.0.M1 <= 9.0.118

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

j0hndo (dohyun4466@gmail.com)
.