Medium severity6.5NVD Advisory· Published Jun 29, 2026· Updated Jul 10, 2026
CVE-2026-55955
CVE-2026-55955
Description
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
Affected products
10- osv-coords7 versionspkg:bitnami/tomcatpkg:rpm/opensuse/tomcat&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/tomcat&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat10&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/tomcat10&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat11&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/tomcat11&distro=openSUSE%20Tumbleweed
< 9.0.119+ 6 more
- (no CPE)range: < 9.0.119
- (no CPE)range: < 9.0.119-160000.1.1
- (no CPE)range: < 9.0.119-1.1
- (no CPE)range: < 10.1.56-160000.1.1
- (no CPE)range: < 10.1.56-1.1
- (no CPE)range: < 11.0.23-160000.1.1
- (no CPE)range: < 11.0.23-1.1
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/29/24nvdThird Party Advisory
- lists.apache.org/thread/g4p5sf45p3f9r011pwqs9r54yd64s106nvdMailing ListVendor Advisory
News mentions
1- Apache Software Foundation: 21 Vulnerabilities Across Multiple Products Disclosed in Early July 2026Vypr Intelligence · Jul 3, 2026