Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-29146

35
FAUCET Score

CVE-2026-29146 is a Padding Oracle vulnerability affecting Apache Tomcat's EncryptInterceptor component when configured with default settings. The vulnerability impacts multiple versions across all actively maintained Tomcat branches: version 11.0.0-M1 through 11.0.18, 10.0.0-M1 through 10.1.52, 9.0.13 through 9.0.115, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109. Remediation is available through upgrades to versions 11.0.19, 10.1.53, and 9.0.116 respectively. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, characterized by a network-based attack vector requiring no authentication or user interaction, making it relatively straightforward to exploit. The primary impact is unauthorized disclosure of sensitive information, with the attack targeting the confidentiality of encrypted data rather than availability or integrity. The EPSS score of 0.001040 suggests this vulnerability currently poses a low probability of exploitation relative to other known CVEs. There is currently no evidence of active exploitation in the wild, as indicated by the absence from the KEV catalog and inactive status on hot vulnerability lists. No publicly available exploit code has been documented in community sources, and limited attention has been directed toward this issue. Organizations should prioritize patching based on their risk tolerance and exposure timeline rather than immediate threat response.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.0.100, <= 7.0.109CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 8.5.38, <= 8.5.100CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 9.0.13, < 9.0.116CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 10.0.0, < 10.1.53CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 11.0.0, < 11.0.20CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
6.26%
Probability of exploitation in next 30 days
EPSS Percentile
92.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0626 is in the 88th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 9.0.116
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 10.1.53
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-tribesFixed in: 9.0.116
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-tribesFixed in: 10.1.53
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-tribesFixed in: 11.0.20
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 11.0.20
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (3)

mavenGHSA-h468-7pvh-8vr8high

Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor

Apr 9, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10899.htmlLOW

[SECURITY] CVE-2026-34486 Apache Tomcat - Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

Apr 9, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10897.html

[SECURITY] CVE-2026-29146 Apache Tomcat - EncryptInterceptor vulnerable to padding oracle attack by default

Apr 9, 2026

References

access.redhat.com / errata/RHSA-2026:20405
access.redhat.com / errata/RHSA-2026:20406
access.redhat.com / errata/RHSA-2026:36787
access.redhat.com / errata/RHSA-2026:36788
access.redhat.com / errata/RHSA-2026:36789
access.redhat.com / errata/RHSA-2026:36790
access.redhat.com / errata/RHSA-2026:36876
access.redhat.com / errata/RHSA-2026:36877
access.redhat.com / errata/RHSA-2026:36878
access.redhat.com / errata/RHSA-2026:36879
access.redhat.com / errata/RHSA-2026:37136
access.redhat.com / errata/RHSA-2026:37137
access.redhat.com / errata/RHSA-2026:38505
access.redhat.com / errata/RHSA-2026:39188
access.redhat.com / errata/RHSA-2026:39189
access.redhat.com / security/cve/CVE-2026-29146
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-29146.json
openwall.com / lists/oss-security/2026/04/09/24
Mailing ListThird Party Advisory
lists.apache.org / thread/lzt04z2pb3dc5tk85obn80xygw3z1p0w
Mailing ListVendor Advisory