Improper access control in Apache Tomcat - CVE-2026-76183
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass security constraints for WebSocket endpoints.
The vulnerability exists due to incorrect parsing of request paths as endpoint templates in WebSocket endpoint processing when processing a request for a WebSocket endpoint. A remote attacker can send a request with a crafted path to bypass security constraints for WebSocket endpoints.