High severity8.1NVD Advisory· Published Aug 25, 2026· Updated Sep 21, 2026
CVE-2026-68569
CVE-2026-68569
Description
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords7 versionspkg:bitnami/tomcatpkg:rpm/opensuse/tomcat&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/tomcat&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat10&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/tomcat10&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat11&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/tomcat11&distro=openSUSE%20Tumbleweed
< 9.0.121+ 6 more
- (no CPE)range: < 9.0.121
- (no CPE)range: < 9.0.121-160000.1.1
- (no CPE)range: < 9.0.121-1.1
- (no CPE)range: < 10.1.59-160000.1.1
- (no CPE)range: < 10.1.59-1.1
- (no CPE)range: < 11.0.25-160000.1.1
- (no CPE)range: < 11.0.25-1.1
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/26/8nvdMailing ListThird Party Advisory
- lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zcnvdMailing ListVendor Advisory
News mentions
2- Apache Tomcat Vulnerabilities Let Attackers Bypass Security Controls and Crash ServersCyber Security News · Aug 27, 2026
- Apache: 25 Vulnerabilities Across Tomcat, Camel, Hive, and More Disclosed Aug 24-26Vypr Intelligence · Aug 26, 2026