Improper Authentication Vulnerability in Apache Tomcat
CVE-2026-68569

8.1HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
25 August 2026

What is CVE-2026-68569?

CVE-2026-68569 is a vulnerability identified in Apache Tomcat, a widely used open-source web server and servlet container. This specific flaw relates to improper authentication mechanisms within the software, which can inadvertently allow a user to be authenticated even if they do not exist in the configured DataSourceRealm. This situation can occur in certain contexts, particularly when using CLIENT-CERT or SPNEGO for authentication. The implications of this vulnerability are significant, as it could permit unauthorized individuals to gain access to applications and data hosted on Apache Tomcat, potentially leading to various security breaches and operational disruptions.

The vulnerability affects multiple versions of Apache Tomcat, including 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.0.M1 through 9.0.120. Additionally, older, end-of-life versions from 8.5.0 through 8.5.100 and from 7.0.0 through 7.0.109 are also known to be vulnerable. Users are advised to upgrade to newer versions that address this authentication flaw, as failure to do so may leave systems exposed to unnecessary risks.

Potential impact of CVE-2026-68569

  1. Unauthorized Access: The primary risk associated with CVE-2026-68569 is the potential for unauthorized users to gain access to the system. This could result in sensitive information exposure, leading to data leaks or unauthorized actions being performed within the web applications hosted on the server.

  2. Data Integrity Violations: With improper authentication, attackers might manipulate or delete data, compromising the integrity of applications and databases. This could disrupt business operations and lead to financial losses.

  3. Compliance and Legal Issues: Organizations may face compliance violations if an unauthorized access incident occurs, especially if they handle sensitive user data subject to regulations such as GDPR or HIPAA. Non-compliance can result in substantial fines and damage to the organization's reputation.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.24

Apache Tomcat 10.1.0-M1 <= 10.1.57

Apache Tomcat 9.0.0.M1 <= 9.0.120

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.