CVE-2026-34486
KEV High · CVSS 7.5- CVSS
- 7.5
- nvd
- EPSS
- 81.2%
- 100th pct
- KEV
- Listed
- 2026-08-04
- Class
- oss containerizable
- CWE-311, CWE-807
Description
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Affected packages
| Bitnami | tomcat | 10.1.53 → 10.1.54 |
| Bitnami | tomcat | 11.0.20 → 11.0.21 |
| Bitnami | tomcat | 9.0.116 → 9.0.117 |
| Maven | org.apache.tomcat:tomcat | 10.1.53 → 10.1.54 |
| Maven | org.apache.tomcat:tomcat | 11.0.20 → 11.0.21 |
| Maven | org.apache.tomcat:tomcat | 9.0.116 → 9.0.117 |
| Maven | org.apache.tomcat:tomcat-tribes | 10.1.53 → 10.1.54 |
| Maven | org.apache.tomcat:tomcat-tribes | 11.0.20 → 11.0.21 |
| Maven | org.apache.tomcat:tomcat-tribes | 9.0.116 → 9.0.117 |
References
- https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
- https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat
- https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat
- https://access.redhat.com/errata/RHSA-2026:36787
- https://access.redhat.com/errata/RHSA-2026:36788
- https://access.redhat.com/errata/RHSA-2026:36789
- https://access.redhat.com/errata/RHSA-2026:36790
- https://access.redhat.com/errata/RHSA-2026:36876
- https://access.redhat.com/errata/RHSA-2026:36877
- https://access.redhat.com/errata/RHSA-2026:36878
- https://access.redhat.com/errata/RHSA-2026:36879
- https://access.redhat.com/errata/RHSA-2026:37136
Status: profiled · ingested 2026-08-05T06:00:54.000Z