CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-55276

Critical · CVSS 9.1

Apache Tomcat — Always-Incorrect Control Flow Implementation (CWE-670) - special roles and empty authorisation constraints omitted from effective web.xml logging

CVSS
9.1
nvd
EPSS
KEV
No
Class
other
CWE-670

Description

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.

Search profile — drives PoC discovery

Symbols effective web.xmlspecial rolesauthorisation constraintsweb.xml logginglogEffectiveWebXmlSecurityConstraintEmptyRoleSemanticPERMITDENY
Keywords CVE-2026-55276Apache TomcatCWE-670effective web.xmlspecial rolesempty authorisation constraintscontrol flowweb.xml logTomcat security constraint loggingTomcat 11.0.22Tomcat 10.1.55Tomcat 9.0.118Tomcat 8.5.100
Versions: 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.0.M1 through 9.0.118, 8.5.0 through 8.5.100

References

Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z