Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Summary
| CVE | CVE-2026-34486 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-09 20:16:25 UTC |
| Updated | 2026-07-20 12:18:48 UTC |
| Description | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.216910000 probability, percentile 0.973680000 (date 2026-07-20)
Problem Types: CWE-311 | CWE-807 | CWE-311 CWE-311 Missing Encryption of Sensitive Data | CWE-807 Reliance on Untrusted Inputs in a Security Decision
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | ADP | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Tomcat | affected 11.0.20 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 10.1.53 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 9.0.116 semver | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:10.1.49-3.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:9.0.117-2.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | unaffected 1:10.1.36-2.el10_0 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | unaffected 1:9.0.87-6.el10_0 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | unaffected 0:7.0.76-18.el7_9 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | unaffected 1:9.0.87-2.el8_10 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | unaffected 1:9.0.87-2.el8_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions | unaffected 1:9.0.87-2.el8_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | unaffected 1:9.0.117-2.el9_8 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions | unaffected 1:9.0.87-2.el9_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions | unaffected 1:9.0.87-2.el9_4 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | unaffected 1:9.0.87-4.el9_6 * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0.0 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0 On RHEL 10 | unaffected 0:11.0.21-5.redhat_00004.1.el10jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0 On RHEL 8 | unaffected 0:11.0.21-5.redhat_00004.1.el8jws * rpm | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 7.0 On RHEL 9 | unaffected 0:11.0.21-5.redhat_00004.1.el9jws * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 5 | Not specified | Not specified |
| ADP | Red Hat | Red Hat JBoss Web Server 6 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache... | af854a3a-2127-422b-91ae-364da2661108 | www.vicarius.io | |
| lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly | [email protected] | lists.apache.org | Mailing List, Vendor Advisory |
| access.redhat.com/errata/RHSA-2026:36877 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36878 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:39188 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-... | af854a3a-2127-422b-91ae-364da2661108 | www.vicarius.io | |
| access.redhat.com/errata/RHSA-2026:36787 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:38505 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36788 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:37137 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36790 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:37136 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36789 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-34486 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36879 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:36876 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:39189 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Bartlomiej Dmitruk at striga.ai (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-04-09T20:01:26.022Z | Reported to Red Hat. |
| ADP | 2026-04-09T19:35:35.994Z | Made public. |
Solutions
ADP: RHSA-2026:39188: Red Hat JBoss Web Server 7.0 on RHEL 10, Red Hat JBoss Web Server 7.0 on RHEL 8, Red Hat JBoss Web Server 7.0 on RHEL 9
ADP: RHSA-2026:38505: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS)
ADP: RHSA-2026:36787: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
ADP: RHSA-2026:36789: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
ADP: RHSA-2026:36788: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:36790: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:37137: Red Hat Enterprise Linux AppStream (v. 8)
ADP: RHSA-2026:37136: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8)
ADP: RHSA-2026:36878: Red Hat Enterprise Linux AppStream E4S (v.9.2)
ADP: RHSA-2026:36876: Red Hat Enterprise Linux AppStream E4S (v.9.4)
ADP: RHSA-2026:36877: Red Hat Enterprise Linux AppStream EUS (v.9.6)
ADP: RHSA-2026:36879: Red Hat Enterprise Linux AppStream (v. 9)
ADP: RHSA-2026:39189: Red Hat JBoss Web Server 7.0.0
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.