OVERVIEW CVE-2026-34486 is a missing encryption vulnerability in Apache Tomcat stemming from an incomplete fix for a previous CVE-2026-29146. The flaw allows attackers to bypass the EncryptInterceptor security mechanism, potentially exposing sensitive data. The vulnerability affects Tomcat versions 11.0.20, 10.1.53, and 9.0.116, with patched versions 11.0.21, 10.1.54, and 9.0.117 now available. SEVERITY This vulnerability carries a HIGH CVSS score of 7.5, indicating significant risk. It is remotely exploitable over the network without requiring authentication, user interaction, or special privileges. The attack has low complexity and results in high impact to confidentiality, as attackers can access sensitive encrypted data without the ability to modify systems or cause denial of service. EXPLOITATION STATUS The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. The EPSS probability score of 0.000090000 suggests minimal likelihood of active exploitation in the wild. However, the FAUCET Risk Score of 48.0/100 indicates moderate concern that warrants timely patching. Organizations should prioritize upgrading affected Tomcat instances to remediated versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.116CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:9.0.116:*:*:*:*:*:*:* | ||
10.1.53CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:10.1.53:*:*:*:*:*:*:* | ||
11.0.20CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:11.0.20:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.