High severity7.5CISA KEVNVD Advisory· Published Apr 9, 2026· Updated Aug 10, 2026
CVE-2026-34486
CVE-2026-34486
Description
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcat-tribesMaven | >= 11.0.20, < 11.0.21 | 11.0.21 |
org.apache.tomcat:tomcat-tribesMaven | >= 10.1.53, < 10.1.54 | 10.1.54 |
org.apache.tomcat:tomcat-tribesMaven | >= 9.0.116, < 9.0.117 | 9.0.117 |
org.apache.tomcat:tomcatMaven | >= 11.0.20, < 11.0.21 | 11.0.21 |
org.apache.tomcat:tomcatMaven | >= 10.1.53, < 10.1.54 | 10.1.54 |
org.apache.tomcat:tomcatMaven | >= 9.0.116, < 9.0.117 | 9.0.117 |
Affected products
66- cpe:2.3:a:redhat:jboss_web_server:7.0.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_tus:8.8:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_els:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.6:*:*:*:*:*:*:*
- osv-coords52 versionspkg:apk/chainguard/ontop-fipspkg:bitnami/tomcatpkg:maven/org.apache.tomcat/tomcatpkg:maven/org.apache.tomcat/tomcat-tribespkg:rpm/almalinux/tomcatpkg:rpm/almalinux/tomcat-admin-webappspkg:rpm/almalinux/tomcat-docs-webapppkg:rpm/almalinux/tomcat-el-3.0-apipkg:rpm/almalinux/tomcat-el-5.0-apipkg:rpm/almalinux/tomcat-jsp-2.3-apipkg:rpm/almalinux/tomcat-jsp-3.1-apipkg:rpm/almalinux/tomcat-libpkg:rpm/almalinux/tomcat-servlet-4.0-apipkg:rpm/almalinux/tomcat-servlet-6.0-apipkg:rpm/almalinux/tomcat-webappspkg:rpm/almalinux/tomcat9pkg:rpm/almalinux/tomcat9-admin-webappspkg:rpm/almalinux/tomcat9-docs-webapppkg:rpm/almalinux/tomcat9-el-3.0-apipkg:rpm/almalinux/tomcat9-jsp-2.3-apipkg:rpm/almalinux/tomcat9-libpkg:rpm/almalinux/tomcat9-servlet-4.0-apipkg:rpm/almalinux/tomcat9-webappspkg:rpm/opensuse/tomcat&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/tomcat&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat10&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/tomcat10&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat11&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/tomcat11&distro=openSUSE%20Tumbleweedpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP7pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP7pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSSpkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6pkg:rpm/suse/tomcat11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP7pkg:rpm/suse/tomcat11&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSSpkg:rpm/suse/tomcat11&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6
< 5.5.0-r4+ 51 more
- (no CPE)range: < 5.5.0-r4
- (no CPE)range: >= 9.0.116, < 9.0.117
- (no CPE)range: >= 11.0.20, < 11.0.21
- (no CPE)range: >= 11.0.20, < 11.0.21
- (no CPE)range: < 1:10.1.49-3.el10_2.alma.1
- (no CPE)range: < 1:10.1.49-3.el10_2.alma.1
- (no CPE)range: < 1:10.1.49-3.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el9_8
- (no CPE)range: < 1:10.1.49-3.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el9_8
- (no CPE)range: < 1:10.1.49-3.el10_2.alma.1
- (no CPE)range: < 1:10.1.49-3.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el9_8
- (no CPE)range: < 1:10.1.49-3.el10_2.alma.1
- (no CPE)range: < 1:10.1.49-3.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el10_2.alma.1
- (no CPE)range: < 1:9.0.117-2.el10_2.alma.1
- (no CPE)range: < 9.0.117-160000.1.1
- (no CPE)range: < 9.0.117-1.1
- (no CPE)range: < 10.1.54-160000.1.1
- (no CPE)range: < 10.1.54-1.1
- (no CPE)range: < 11.0.21-160000.1.1
- (no CPE)range: < 11.0.21-1.1
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-3.163.2
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-3.163.2
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 9.0.117-150200.105.1
- (no CPE)range: < 10.1.54-150200.5.64.1
- (no CPE)range: < 10.1.54-150200.5.64.1
- (no CPE)range: < 10.1.54-150200.5.64.1
- (no CPE)range: < 10.1.54-150200.5.64.1
- (no CPE)range: < 10.1.54-150200.5.64.1
- (no CPE)range: < 10.1.54-150200.5.64.1
- (no CPE)range: < 10.1.54-150200.5.64.1
- (no CPE)range: < 11.0.21-150600.13.18.1
- (no CPE)range: < 11.0.21-150600.13.18.1
- (no CPE)range: < 11.0.21-150600.13.18.1
Patches
Vulnerability mechanics
References
30- access.redhat.com/errata/RHSA-2026:36787nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36788nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36789nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36790nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36876nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36877nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36878nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36879nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:37136nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:37137nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:38505nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:39188nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:39189nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2026-34486nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/advisories/GHSA-69r9-qgr7-g2wjghsaADVISORY
- lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrlynvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-34486ghsaADVISORY
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.jsonnvdThird Party Advisory
- socradar.io/blog/snowlight-government-chinese-campaign/nvdThird Party Advisory
- www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcatnvdThird Party AdvisoryWEB
- www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcatnvdMitigationThird Party AdvisoryWEB
- github.com/apache/tomcat/commit/1fab40ccc752e22639eccfe290d5624afad7eccdghsaWEB
- github.com/apache/tomcat/commit/55f3eb9148233054fccfdf761141c6894a050be1ghsaWEB
- github.com/apache/tomcat/commit/776e12b3e2b0b4507b8a3b62c187ceb0b74bf418ghsaWEB
- tomcat.apache.org/security-10.htmlghsaWEB
- tomcat.apache.org/security-11.htmlghsaWEB
- tomcat.apache.org/security-9.htmlghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.herodevs.com/vulnerability-directory/cve-2026-34486ghsaWEB
News mentions
10- The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposureTenable Blog · Aug 15, 2026
- Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 StoriesCyber Security News · Aug 9, 2026
- CISA Warns of Exploited Langflow, N-central, and Tomcat VulnerabilitiesSecurityWeek · Aug 5, 2026
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively ExploitedThe Hacker News · Aug 5, 2026
- CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in AttacksCyber Security News · Aug 5, 2026
- Apache CVE-2026-34486 Zero-Day Added to CISA KEV Under Active ExploitationVypr Intelligence · Aug 4, 2026
- Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsInfosecurity Magazine · Jul 31, 2026
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesThe Hacker News · Jul 30, 2026
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous CyberattacksUnit 42 · Jul 30, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts