← back
CVE-2026-34486highunder attackCWE-311CWE-807

Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.5epss 81%
from disclosure to weapon32 days
Published on NVDApr 9
1st PoC+32d
CISA KEV+117d
exploitation probability
81%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2026-08-07

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

Apache Tomcat has a flaw where sensitive data encryption can be bypassed due to an incomplete fix. This means attackers could intercept and read private information that should have been protected.

Technical detail

CVE-2026-34486 involves a bypass of the EncryptInterceptor mechanism in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116. The vulnerability stems from an insufficient fix to CVE-2026-29146, allowing attackers to circumvent encryption protections for sensitive data in transit. Exploitation requires network-level access to intercepted communications, with impact ranging from confidentiality breach of encrypted payloads.

Summary generated and translated by AI from the official description.
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.