Authentication Bypass Vulnerability in Apache Tomcat
CVE-2026-86248

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86248?

A vulnerability in Apache Tomcat allows CLIENT_CERT authentication to not fail as expected under certain conditions when the soft fail feature is disabled. This poses a risk as attackers may exploit this oversight to gain unauthorized access. Affected versions span across Apache Tomcat 11.0.0-M14 to 11.0.25, 10.1.22 to 10.1.59, and 9.0.92 to 9.0.121. Users are urged to update to the latest patched versions to mitigate this vulnerability.

Affected Version(s)

Apache Tomcat 11.0.0-M14 <= 11.0.25

Apache Tomcat 10.1.22 <= 10.1.59

Apache Tomcat 9.0.92 <= 9.0.121

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Read (github.com/Michael-JRead)
.