{"id":"CVE-2026-34486","aliases":["BIT-tomcat-2026-34486","GHSA-69r9-qgr7-g2wj"],"url":"https://o3.security/vulnerability/CVE-2026-34486","summary":"Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor","details":"Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\n\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\n\nUsers are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.","published":"2026-04-09T19:35:35.994Z","modified":"2026-09-22T03:30:54.467844603Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.98616,"percentile":0.99921,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat-tribes","fixedVersion":"11.0.21"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat-tribes","fixedVersion":"10.1.54"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat-tribes","fixedVersion":"9.0.117"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat","fixedVersion":"11.0.21"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat","fixedVersion":"10.1.54"},{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat","fixedVersion":"9.0.117"}],"fix":null,"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36787"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36788"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36789"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36790"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36876"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36877"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36878"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36879"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37136"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37137"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:38505"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39188"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39189"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-34486"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34486.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34486"},{"type":"ADVISORY","url":"https://socradar.io/blog/snowlight-government-chinese-campaign/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2457027"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-22T03:30:54.467844603Z"}}