Improper Certificate Validation in Apache Tomcat - CVE-2026-86248
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass client certificate authentication.
The vulnerability exists due to improper certificate validation in CLIENT_CERT authentication when validating OCSP status with OCSP soft fail disabled. A remote attacker can present a certificate in affected scenarios to bypass client certificate authentication.
The issue occurs in some scenarios when OCSP soft fail is disabled.