SB2026082616 - Multiple vulnerabilities in Apache Tomcat
Published: August 26, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-65182)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security constraints.
The vulnerability exists due to improper access control in security constraint processing when handling requests for paths with overlapping constraints. A remote attacker can send a crafted request to bypass security constraints.
The issue occurs if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.
2) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-65183)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to access the Unix domain socket.
The vulnerability exists due to a race condition in Unix domain socket creation when setting specific permissions. A local user can win the race during socket creation to access the Unix domain socket.
3) Improper access control (CVE-ID: CVE-2026-65637)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass strict SNI validation.
The vulnerability exists due to improper access control in the HTTP/2 request handling when processing requests without an authority field. A remote attacker can send a specially crafted HTTP/2 request to bypass strict SNI validation.
The issue is related to an incomplete fix for a previous vulnerability.
4) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-65905)
CWE-ID: CWE-294 - Authentication Bypass by Capture-replay
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to replay a DIGEST-authenticated request once.
The vulnerability exists due to improper authentication in DIGEST authentication replay protection when processing a DIGEST-authenticated request with a nonceCount on the upper boundary of the replay window before windowSize requests had been made. A remote user can send and replay a crafted DIGEST-authenticated request to replay a DIGEST-authenticated request once.
The issue only occurs while the associated nonceCount remains within the replay window.
5) Off-by-one (CVE-ID: CVE-2026-65927)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass access control.
The vulnerability exists due to an off-by-one error in RewriteValve when processing rewrite rules that use the [N] flag. A remote attacker can trigger rewrite processing to restart at the second rule instead of the first rule to bypass access control.
6) Improper access control (CVE-ID: CVE-2026-66422)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass declarative role constraints.
The vulnerability exists due to improper access control in Realm role handling when processing security-role-ref definitions. A remote user can use servlet role references as role aliases to bypass declarative role constraints.
7) Improper access control (CVE-ID: CVE-2026-68525)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass method-specific access controls.
The vulnerability exists due to improper access control in the FORM authentication process when handling a redirect after authentication. A remote user can complete FORM authentication and use the redirect flow to bypass method-specific access controls.
The issue affects constraints that restrict access to a resource for POST requests but not GET requests.
8) Improper Authentication (CVE-ID: CVE-2026-68569)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass authentication.
The vulnerability exists due to improper authentication in DataSourceRealm and JDBCRealm when processing principal lookups for certain authentication methods. A remote user can authenticate with CLIENT-CERT or SPNEGO even if the user does not exist in the configured realm to bypass authentication.
The issue affects some authentication methods, including CLIENT-CERT and SPNEGO.
9) Memory leak (CVE-ID: CVE-2026-68763)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an allocation leak in HTTP/2 backlog tracking when processing a reset stream. A remote attacker can reset a stream to cause a denial of service.
10) Insufficient Session Expiration (CVE-ID: CVE-2026-73180)
CWE-ID: CWE-613 - Insufficient Session Expiration
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to maintain an authenticated websocket session after the associated http session has ended.
The vulnerability exists due to improper session management in the websocket session handling when the session id of an authenticated http session is changed after a websocket connection has been established. A remote user can continue using the websocket connection to maintain an authenticated websocket session after the associated http session has ended.
The issue occurs only if the session id for the authenticated http session is changed after the websocket connection has already been established.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=bn0mtpf9p54to6lnm0r07lt9jlvp0goj
- https://tomcat.apache.org/security-11.html
- https://lists.apache.org/api/email.lua?id=y7q483yscyw3hrmb8k1tt8dm5mjzq13o
- https://lists.apache.org/api/email.lua?id=dch3wv5ol5t8o4cymh9kbkzrj732prhc
- https://lists.apache.org/api/email.lua?id=qbq555o6722xw4t37l28y03h4x1cnyzx
- https://lists.apache.org/api/email.lua?id=hk722clhsxqxwkjqjys0kmljmlnhhllp
- https://lists.apache.org/api/email.lua?id=dywhxs7v9c9ww1xvv7h4102vn50hx3sh
- https://lists.apache.org/api/email.lua?id=9jwxxmr6dqx1h514k6omvmj0fxvbmtcb
- https://lists.apache.org/api/email.lua?id=rqfzjrdzh4c39tw8qpv6dm8xohtc7gjv
- https://lists.apache.org/api/email.lua?id=s9n55wcm58vk9orlkn7l0sb7j4xfnrgq
- https://lists.apache.org/api/email.lua?id=g0dvvbt0ksxhcork9r9nl41w2jl21wfh