Improper Authentication Vulnerability in Apache Tomcat
CVE-2026-68569
Currently unrated
What is CVE-2026-68569?
An improper authentication vulnerability in Apache Tomcat impacts user authentication processes, particularly in contexts such as CLIENT-CERT and SPNEGO. In certain scenarios, this vulnerability permits users to be authenticated even if they do not exist in the DataSourceRealm, posing a significant risk to systems relying on this authentication framework. Users are urged to upgrade to secure versions 11.0.25, 10.1.58, or 9.0.121 to mitigate this issue effectively.
Affected Version(s)
Apache Tomcat 11.0.0-M1 <= 11.0.24
Apache Tomcat 10.1.0-M1 <= 10.1.57
Apache Tomcat 9.0.0.M1 <= 9.0.120