Always-Incorrect Control Flow Implementation in Apache Tomcat - CVE-2026-55276
Published: June 30, 2026
Apache Tomcat
Detailed vulnerability description
The vulnerability allows a local user to obtain incomplete security configuration information.
The vulnerability exists due to logic errors in effective web.xml generation in the logged effective web.xml output when generating configuration logs. A local user can review the logged output to obtain incomplete security configuration information.
Special roles and empty authorization constraints are omitted from the logged effective web.xml.
How to mitigate CVE-2026-55276
Sources
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.56
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.23
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.119
- https://github.com/apache/tomcat/commit/25677f90fd721c26ef0f613d34ef8275b1aafc31