← Back to CVE List
CVE-2026-34486NVD
Vulnerability Summary
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone
External References
- https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
- https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat
- https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat
- https://access.redhat.com/errata/RHSA-2026:36787
- https://access.redhat.com/errata/RHSA-2026:36788
- https://access.redhat.com/errata/RHSA-2026:36789
- https://access.redhat.com/errata/RHSA-2026:36790
- https://access.redhat.com/errata/RHSA-2026:36876
- https://access.redhat.com/errata/RHSA-2026:36877
- https://access.redhat.com/errata/RHSA-2026:36878
- https://access.redhat.com/errata/RHSA-2026:36879
- https://access.redhat.com/errata/RHSA-2026:37136
- https://access.redhat.com/errata/RHSA-2026:37137
- https://access.redhat.com/errata/RHSA-2026:38505
- https://access.redhat.com/errata/RHSA-2026:39188
- https://access.redhat.com/errata/RHSA-2026:39189
- https://access.redhat.com/security/cve/CVE-2026-34486
- https://bugzilla.redhat.com/show_bug.cgi?id=2457027
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json