Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Summary
| CVE | CVE-2026-34486 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-09 20:16:25 UTC |
| Updated | 2026-08-10 13:19:04 UTC |
| Description | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.829330000 probability, percentile 0.996480000 (date 2026-08-21)
CISA KEV: Listed on 2026-08-04; due 2026-08-07; ransomware use Unknown
Problem Types: CWE-311 | CWE-807 | CWE-311 CWE-311 Missing Encryption of Sensitive Data | CWE-807 Reliance on Untrusted Inputs in a Security Decision
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | ADP | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA Known Exploited Vulnerability
| Vendor | Apache |
|---|---|
| Product | Tomcat |
| Name | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability |
| Required Action | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. |
| Notes | https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34486 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Tomcat | 10.1.53 | All | All | All |
| Application | Apache | Tomcat | 11.0.20 | All | All | All |
| Application | Apache | Tomcat | 9.0.116 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 10.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 9.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Els | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 10.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Tus | 8.8 | All | All | All |
| Operating System | Redhat | Enterprise Linux Update Services For Sap Solutions | 8.8 | All | All | All |
| Operating System | Redhat | Enterprise Linux Update Services For Sap Solutions | 9.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux Update Services For Sap Solutions | 9.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux Update Services For Sap Solutions | 9.6 | All | All | All |
| Application | Redhat | Jboss Web Server | 7.0.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Tomcat | affected 11.0.20 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 10.1.53 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 9.0.116 semver | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:10.1.49-3.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:9.0.117-2.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | unaffected 1:10.1.36-2.el10_0 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | unaffected 1:9.0.87-6.el10_0 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | unaffected 0:7.0.76-18.el7_9 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | unaffected 1:9.0.87-2.el8_10 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | unaffected 1:9.0.87-2.el8_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions | unaffected 1:9.0.87-2.el8_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | unaffected 1:9.0.117-2.el9_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions | unaffected 1:9.0.87-2.el9_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions | unaffected 1:9.0.87-2.el9_4 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | unaffected 1:9.0.87-4.el9_6 * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0.0 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0 On RHEL 10 | unaffected 0:11.0.21-5.redhat_00004.1.el10jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0 On RHEL 8 | unaffected 0:11.0.21-5.redhat_00004.1.el8jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0 On RHEL 9 | unaffected 0:11.0.21-5.redhat_00004.1.el9jws * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 5 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache... | af854a3a-2127-422b-91ae-364da2661108 | www.vicarius.io | Mitigation, Third Party Advisory |
| lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly | [email protected] | lists.apache.org | Mailing List, Vendor Advisory |
| access.redhat.com/errata/RHSA-2026:36877 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:36878 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:39188 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-... | af854a3a-2127-422b-91ae-364da2661108 | www.vicarius.io | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:36787 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:38505 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:36788 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:37137 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| socradar.io/blog/snowlight-government-chinese-campaign | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | socradar.io | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:36790 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:37136 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| access.redhat.com/errata/RHSA-2026:36789 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| access.redhat.com/security/cve/CVE-2026-34486 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:36879 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:36876 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:39189 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
CNA: Bartlomiej Dmitruk at striga.ai (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-04-09T20:01:26.022Z | Reported to Red Hat. |
| ADP | 2026-04-09T19:35:35.994Z | Made public. |
Solutions
ADP: RHSA-2026:39188: Red Hat JBoss Web Server 7.0 on RHEL 10, Red Hat JBoss Web Server 7.0 on RHEL 8, Red Hat JBoss Web Server 7.0 on RHEL 9
ADP: RHSA-2026:38505: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS)
ADP: RHSA-2026:36787: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
ADP: RHSA-2026:36789: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
ADP: RHSA-2026:36788: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:36790: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:37137: Red Hat Enterprise Linux AppStream (v. 8)
ADP: RHSA-2026:37136: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8)
ADP: RHSA-2026:36878: Red Hat Enterprise Linux AppStream E4S (v.9.2)
ADP: RHSA-2026:36876: Red Hat Enterprise Linux AppStream E4S (v.9.4)
ADP: RHSA-2026:36877: Red Hat Enterprise Linux AppStream EUS (v.9.6)
ADP: RHSA-2026:36879: Red Hat Enterprise Linux AppStream (v. 9)
ADP: RHSA-2026:39189: Red Hat JBoss Web Server 7.0.0
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.