Missing Authentication Step in Apache Tomcat Affects Multiple Versions
CVE-2026-55957

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 June 2026

What is CVE-2026-55957?

An authentication vulnerability has been identified in Apache Tomcat, specifically relating to the configuration of JNDIRealm when using GSSAPI for authentication purposes. This flaw enables unauthorized attackers to authenticate without providing the correct password, thereby compromising the security of the affected Tomcat instances. It is crucial for users operating any version from 11.0.0-M1 through 11.0.4, 10.1.0-M1 through 10.1.36, 9.0.0.M1 through 9.0.100, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109 to upgrade to the latest versions, which remedy this vulnerability.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.4

Apache Tomcat 10.1.0-M1 <= 10.1.36

Apache Tomcat 9.0.0.M1 <= 9.0.100

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ilan Toyter
.