← Back to browse · API

CVE-2026-34486

Severity
HIGH
CVSS
7.5
EPSS
0.8116
Risk score
83.41
CISA KEV
Yes
PoC
Yes
Published
2026-04-09
Modified
2026-08-06
First seen
2026-08-05
Aliases
EUVD-2026-21056, GHSA-69R9-QGR7-G2WJ
Products
Apache Software Foundation:Apache Tomcat 10.1.53, Apache Software Foundation:Apache Tomcat 11.0.20, Apache Software Foundation:Apache Tomcat 9.0.116, Apache:Tomcat, apache:tomcat, redhat:enterprise_linux, redhat:enterprise_linux_els, redhat:enterprise_linux_eus, redhat:enterprise_linux_tus, redhat:enterprise_linux_update_services_for_sap_solutions, redhat:jboss_web_server
Sources
nvd CVE-2026-34486
euvd EUVD-2026-21056
cisa.gov CVE-2026-34486
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-34486

Description

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

References