CVE-2026-29145 is a critical authentication bypass vulnerability in Apache Tomcat and Tomcat Native where CLIENT_CERT authentication fails to properly validate certificates when soft fail is disabled. The vulnerability affects multiple versions: Tomcat versions 9.0.83-9.0.115, 10.1.0-M7-10.1.52, and 11.0.0-M1-11.0.18, along with corresponding Tomcat Native releases. Patches are available in Tomcat 9.0.116, 10.1.53, 11.0.20 and Tomcat Native 1.3.7, 2.0.14, and later versions. The vulnerability carries a CVSS score of 9.1 (Critical) with a network-based attack vector requiring no authentication or user interaction, indicating high exploitability. The impact includes both confidentiality and integrity compromise, though availability is not affected. This severity rating reflects the authentication mechanism's fundamental role in protecting sensitive applications. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog, and there is no evidence of active exploitation in the wild. The EPSS score of 0.0012 indicates low current exploitation probability relative to other vulnerabilities, and the vulnerability remains inactive on threat intelligence hot lists. However, organizations running affected Tomcat versions should prioritize patching due to the critical nature of authentication bypass vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.83, < 9.0.116CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 10.1.1, < 10.1.53CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.20CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
10.1.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:10.1.0:-:*:*:*:*:*:* | ||
10.1.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
Apr 9, 2026[SECURITY] CVE-2026-29145 Apache Tomcat and Tomcat Native - OCSP checks sometimes soft-fail even when soft-fail is disabled
Apr 9, 2026