Race condition in Apache Tomcat Native - CVE-2026-86247
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass client certificate verification requirements.
The vulnerability exists due to a race condition in Apache Tomcat Native when verifying client certificates. A remote attacker can exploit the race condition to bypass client certificate verification requirements.
Only some configurations are affected.