Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34486

69
FAUCET Score

OVERVIEW CVE-2026-34486 is a missing encryption vulnerability in Apache Tomcat stemming from an incomplete fix for a previous CVE-2026-29146. The flaw allows attackers to bypass the EncryptInterceptor security mechanism, potentially exposing sensitive data. The vulnerability affects Tomcat versions 11.0.20, 10.1.53, and 9.0.116, with patched versions 11.0.21, 10.1.54, and 9.0.117 now available. SEVERITY This vulnerability carries a HIGH CVSS score of 7.5, indicating significant risk. It is remotely exploitable over the network without requiring authentication, user interaction, or special privileges. The attack has low complexity and results in high impact to confidentiality, as attackers can access sensitive encrypted data without the ability to modify systems or cause denial of service. EXPLOITATION STATUS The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. The EPSS probability score of 0.000090000 suggests minimal likelihood of active exploitation in the wild. However, the FAUCET Risk Score of 48.0/100 indicates moderate concern that warrants timely patching. Organizations should prioritize upgrading affected Tomcat instances to remediated versions.

Impacted Technologies

VendorProductVersion(s)CPE
9.0.116CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:9.0.116:*:*:*:*:*:*:*
10.1.53CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:10.1.53:*:*:*:*:*:*:*
11.0.20CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:11.0.20:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
42.63%
Probability of exploitation in next 30 days
EPSS Percentile
98.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-34486 · May 12, 2026
This CVE's current EPSS score of 0.4263 is in the 97th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 11.0.21
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 10.1.54
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 9.0.117
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-tribesFixed in: 11.0.21
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-tribesFixed in: 10.1.54
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-tribesFixed in: 9.0.117
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

mavenGHSA-69r9-qgr7-g2wjhigh

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

Apr 9, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10899.htmlLOW

[SECURITY] CVE-2026-34486 Apache Tomcat - Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

Apr 9, 2026

References

access.redhat.com / errata/RHSA-2026:36787
access.redhat.com / errata/RHSA-2026:36788
access.redhat.com / errata/RHSA-2026:36789
access.redhat.com / errata/RHSA-2026:36790
access.redhat.com / errata/RHSA-2026:36876
access.redhat.com / errata/RHSA-2026:36877
access.redhat.com / errata/RHSA-2026:36878
access.redhat.com / errata/RHSA-2026:36879
access.redhat.com / errata/RHSA-2026:37136
access.redhat.com / errata/RHSA-2026:37137
access.redhat.com / errata/RHSA-2026:38505
access.redhat.com / errata/RHSA-2026:39188
access.redhat.com / errata/RHSA-2026:39189
access.redhat.com / security/cve/CVE-2026-34486
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-34486.json
vicarius.io / vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat
vicarius.io / vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat
lists.apache.org / thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
Mailing ListVendor Advisory