CVE-2026-29146 is a Padding Oracle vulnerability affecting Apache Tomcat's EncryptInterceptor component when configured with default settings. The vulnerability impacts multiple versions across all actively maintained Tomcat branches: version 11.0.0-M1 through 11.0.18, 10.0.0-M1 through 10.1.52, 9.0.13 through 9.0.115, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109. Remediation is available through upgrades to versions 11.0.19, 10.1.53, and 9.0.116 respectively. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, characterized by a network-based attack vector requiring no authentication or user interaction, making it relatively straightforward to exploit. The primary impact is unauthorized disclosure of sensitive information, with the attack targeting the confidentiality of encrypted data rather than availability or integrity. The EPSS score of 0.001040 suggests this vulnerability currently poses a low probability of exploitation relative to other known CVEs. There is currently no evidence of active exploitation in the wild, as indicated by the absence from the KEV catalog and inactive status on hot vulnerability lists. No publicly available exploit code has been documented in community sources, and limited attention has been directed toward this issue. Organizations should prioritize patching based on their risk tolerance and exposure timeline rather than immediate threat response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.100, <= 7.0.109CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 8.5.38, <= 8.5.100CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 9.0.13, < 9.0.116CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.1.53CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.20CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
Apr 9, 2026[SECURITY] CVE-2026-34486 Apache Tomcat - Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Apr 9, 2026[SECURITY] CVE-2026-29146 Apache Tomcat - EncryptInterceptor vulnerable to padding oracle attack by default
Apr 9, 2026