Missing Authentication Step in Apache Tomcat Affects Multiple Versions
CVE-2026-55957
Currently unrated
What is CVE-2026-55957?
An authentication vulnerability has been identified in Apache Tomcat, specifically relating to the configuration of JNDIRealm when using GSSAPI for authentication purposes. This flaw enables unauthorized attackers to authenticate without providing the correct password, thereby compromising the security of the affected Tomcat instances. It is crucial for users operating any version from 11.0.0-M1 through 11.0.4, 10.1.0-M1 through 10.1.36, 9.0.0.M1 through 9.0.100, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109 to upgrade to the latest versions, which remedy this vulnerability.
Affected Version(s)
Apache Tomcat 11.0.0-M1 <= 11.0.4
Apache Tomcat 10.1.0-M1 <= 10.1.36
Apache Tomcat 9.0.0.M1 <= 9.0.100