tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure

cve CVE-2026-68569 2 sources, 2 claims · Watch

Red Hat writes:
tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure the claim
Severity
HIGH NVD
important Red Hat
CVSS they disagree
8.1 NVD
8.2 Red Hat
Vendor
Apache Software Foundation NVD
Product
Apache Tomcat NVD
CWE
CWE-287 NVD
CWE-305 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Why the CVSS differs

MetricNVDRed Hat
Attack vector AVnetwork Nnetwork N
Attack complexity AClow Llow L
Privileges required PRlow Lnone N
User interaction UInone Nnone N
Scope Sunchanged Uunchanged U
Confidentiality Chigh Hhigh H
Integrity Ihigh Hlow L
Availability Anone Nnone N

Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.

Timeline

2026-08-25first spoke of it: Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.NVD
2026-08-25first spoke of it: tomcat: Apache Tomcat: Improper Authentication due to principal lookup failureRed Hat

What it is to other things

affectsapache/tomcat
NVD
made_byapache
NVD

In words only, so not counted until a person confirms one:

made_byapache_software_foundation
NVD says “Apache Software Foundation”
affectsapache_software_foundation/apache_tomcat
NVD says “Apache Software Foundation · Apache Tomcat”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
NVD8.1
receipt
Source
NVD
Its words
8.1
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
Red Hat8.2
receipt
Source
Red Hat
Its words
8.2
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-68569",
  "CWE": "CWE-305",
  "advisories": [
    "RHSA-2026:73981",
    "RHSA-2026:68257",
    "RHSA-2026:73982",
    "RHSA-2026:68258"
  ],
  "affected_packages": [
    "tomcat11-main-11.0.26-0.1.hum1",
    "tomcat",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el9jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el8jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el10jws",
    "tomcat10-main-10.1.60-0.1.hum1"
  ],
  "bugzilla": "2524160",
  "bugzilla_description": "tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-25T21:59:17Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-68569.json",
  "severity": "important"
}
—
CVSS vector
cvss_vector
not compared
NVDCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
Red HatCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2026-68569",
  "CWE": "CWE-305",
  "advisories": [
    "RHSA-2026:73981",
    "RHSA-2026:68257",
    "RHSA-2026:73982",
    "RHSA-2026:68258"
  ],
  "affected_packages": [
    "tomcat11-main-11.0.26-0.1.hum1",
    "tomcat",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el9jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el8jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el10jws",
    "tomcat10-main-10.1.60-0.1.hum1"
  ],
  "bugzilla": "2524160",
  "bugzilla_description": "tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-25T21:59:17Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-68569.json",
  "severity": "important"
}
—
CWE
cwe
different words
NVDCWE-287
receipt
Source
NVD
Its words
CWE-287
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-287
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-305
receipt
Source
Red Hat
Its words
CWE-305
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-68569",
  "CWE": "CWE-305",
  "advisories": [
    "RHSA-2026:73981",
    "RHSA-2026:68257",
    "RHSA-2026:73982",
    "RHSA-2026:68258"
  ],
  "affected_packages": [
    "tomcat11-main-11.0.26-0.1.hum1",
    "tomcat",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el9jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el8jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el10jws",
    "tomcat10-main-10.1.60-0.1.hum1"
  ],
  "bugzilla": "2524160",
  "bugzilla_description": "tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-25T21:59:17Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-68569.json",
  "severity": "important"
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Packages
packages
Red Hattomcat11-main-11.0.26-0.1.hum1, tomcat, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el9jws, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el8jws, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el10jws, tomcat10-main-10.1.60-0.1.hum1
receipt
Source
Red Hat
Its words
tomcat11-main-11.0.26-0.1.hum1, tomcat, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el9jws, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el8jws, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el10jws, tomcat10-main-10.1.60-0.1.hum1
Read by
field:affected_packages[]
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCtomcat11-main-11.0.26-0.1.hum1, tomcat, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el9jws, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el8jws, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el10jws, tomcat10-main-10.1.60-0.1.hum1
2026-09-29 09:44 UTCtomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1
What the source handed over
{
  "CVE": "CVE-2026-68569",
  "CWE": "CWE-305",
  "advisories": [
    "RHSA-2026:73981",
    "RHSA-2026:68257",
    "RHSA-2026:73982",
    "RHSA-2026:68258"
  ],
  "affected_packages": [
    "tomcat11-main-11.0.26-0.1.hum1",
    "tomcat",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el9jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el8jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el10jws",
    "tomcat10-main-10.1.60-0.1.hum1"
  ],
  "bugzilla": "2524160",
  "bugzilla_description": "tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-25T21:59:17Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-68569.json",
  "severity": "important"
}
—
Product
product
NVDApache Tomcat
receipt
Source
NVD
Its words
Apache Tomcat
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCApache Tomcat
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDHIGH
From 7.0 to 8.9.
receipt
Source
NVD
Its words
HIGH
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCHIGH
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
high
Severity
severity
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-68569",
  "CWE": "CWE-305",
  "advisories": [
    "RHSA-2026:73981",
    "RHSA-2026:68257",
    "RHSA-2026:73982",
    "RHSA-2026:68258"
  ],
  "affected_packages": [
    "tomcat11-main-11.0.26-0.1.hum1",
    "tomcat",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el9jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el8jws",
    "jws6-tomcat-0:10.1.49-16.redhat_00016.1.el10jws",
    "tomcat10-main-10.1.60-0.1.hum1"
  ],
  "bugzilla": "2524160",
  "bugzilla_description": "tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-25T21:59:17Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-68569.json",
  "severity": "important"
}
high
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDtotal
The attacker gains full control of the component, or all of its information.
receipt
Source
NVD
Its words
total
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCtotal
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApache Software Foundation
receipt
Source
NVD
Its words
Apache Software Foundation
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCApache Software Foundation
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Tomcat",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "11.0.24",
                "status": "affected",
                "version": "11.0.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "10.1.57",
                "status": "affected",
                "version": "10.1.0-M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "9.0.120",
                "status": "affected",
                "version": "9.0.0.M1",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "8.5.100",
                "status": "affected",
                "version": "8.5.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.0.109",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              },
              {
                "lessThan": "7.0.0",
                "status": "unknown",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5BE0EC99-5BCD-4F7F-8124-4A1734B7BF6B",
                "versionEndIncluding": "7.0.109",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F374FF7-8FFF-476A-8F8B-7BD7597FD546",
                "versionEndExcluding": "9.0.121",
                "versionStartIncluding": "8.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DA02FDED-4F4C-4869-ADE9-03940EFA84FA",
                "versionEndExcluding": "10.1.58",
                "versionStartIncluding": "10.1.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAF1D122-DBBD-4352-A9DB-61BC216F2C45",
                "versionEndExcluding": "11.0.25",
                "versionStartIncluding": "11.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue."
      }
    ],
    "id": "CVE-2026-68569",
    "lastModified": "2026-09-21T12:17:17.257",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-68569",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-26T18:38:39.170628Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-25T22:17:05.837",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/08/26/8"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-287"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure
zetlyn/cve-redhat · 2026-08-25
cvss 8.2 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N cwe CWE-305 packages tomcat11-main-11.0.26-0.1.hum1, tomcat, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el9jws, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el8jws, jws6-tomcat-0:10.1.49-16.redhat_00016.1.el10jws, tomcat10-main-10.1.60-0.1.hum1 severity important source
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
zetlyn/cve-nvd · 2026-08-25
automatable no cvss 8.1 cvss_vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N cwe CWE-287 exploitation none product Apache Tomcat severity HIGH status Analyzed technical_impact total vendor Apache Software Foundation source