Authentication Bypass in Apache Tomcat WebSocket Endpoints
CVE-2026-76183

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-76183?

An authentication bypass vulnerability exists in Apache Tomcat that allows attackers to circumvent security constraints for WebSocket endpoints. This flaw affects multiple versions of Apache Tomcat, allowing unauthorized access and control over user sessions. To mitigate this risk, users should upgrade to Apache Tomcat versions 11.0.26, 10.1.60, or 9.0.122, which address the identified vulnerabilities.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.25

Apache Tomcat 10.1.0-M1 <= 10.1.59

Apache Tomcat 9.0.0.M1 <= 9.0.121

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.