Authentication Bypass Vulnerability in Apache Tomcat
CVE-2026-86248
Currently unrated
What is CVE-2026-86248?
A vulnerability in Apache Tomcat allows CLIENT_CERT authentication to not fail as expected under certain conditions when the soft fail feature is disabled. This poses a risk as attackers may exploit this oversight to gain unauthorized access. Affected versions span across Apache Tomcat 11.0.0-M14 to 11.0.25, 10.1.22 to 10.1.59, and 9.0.92 to 9.0.121. Users are urged to update to the latest patched versions to mitigate this vulnerability.
Affected Version(s)
Apache Tomcat 11.0.0-M14 <= 11.0.25
Apache Tomcat 10.1.22 <= 10.1.59
Apache Tomcat 9.0.92 <= 9.0.121