CVE Details

CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Published: 2026-08-04 CVSS: 7.5 HIGH Product: Apache Tomcat Due Date: 2026-08-07

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • 0xMarcio/cve • ⭐ 1352 • 2024-05-24 • Conf: 85.0%
  • Latest CVEs with their Proof of Concept exploits.
  • striga-ai/CVE-2026-34486 • ⭐ 69 • 2026-05-11 • Conf: 95.0%
  • EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.
  • 404-src/CVE-2026-34486 • ⭐ 8 • 2026-04-15 • Conf: 95.0%
  • Apache Tomcat EncryptInterceptor Bypass → Unauthenticated RCE (CVE-2026-34486)

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 7.5
  • Severity: HIGH
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: partial

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-34486
cveMetadata > assignerOrgId f0158376-9dc2-43b6-827c-5f631a4d8d09
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName apache
cveMetadata > dateReserved 2026-03-30T07:57:49.315Z
cveMetadata > datePublished 2026-04-09T19:35:35.994Z
cveMetadata > dateUpdated 2026-08-04T19:58:24.191Z
containers > cna > affected > 0 > defaultStatus unaffected
containers > cna > affected > 0 > product Apache Tomcat
containers > cna > affected > 0 > vendor Apache Software Foundation
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version 11.0.20
containers > cna > affected > 0 > versions > 0 > versionType semver
containers > cna > affected > 0 > versions > 1 > status affected
containers > cna > affected > 0 > versions > 1 > version 10.1.53
containers > cna > affected > 0 > versions > 1 > versionType semver
containers > cna > affected > 0 > versions > 2 > status affected
containers > cna > affected > 0 > versions > 2 > version 9.0.116
containers > cna > affected > 0 > versions > 2 > versionType semver
containers > cna > credits > 0 > lang en
containers > cna > credits > 0 > type finder
containers > cna > credits > 0 > value Bartlomiej Dmitruk at striga.ai
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > supportingMedia > 0 > base64 False
containers > cna > descriptions > 0 > supportingMedia > 0 > type text/html
containers > cna > descriptions > 0 > supportingMedia > 0 > value <p>Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the&nbsp;fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.</p><p>This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.</p><p>Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.</p>
containers > cna > descriptions > 0 > value Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
containers > cna > metrics > 0 > other > content > text important
containers > cna > metrics > 0 > other > type Textual description of severity
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-311
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-311 Missing Encryption of Sensitive Data
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > providerMetadata > orgId f0158376-9dc2-43b6-827c-5f631a4d8d09
containers > cna > providerMetadata > shortName apache
containers > cna > providerMetadata > dateUpdated 2026-04-09T19:35:35.994Z
containers > cna > references > 0 > tags > 0 vendor-advisory
containers > cna > references > 0 > url https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
containers > cna > source > discovery EXTERNAL
containers > cna > title Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
containers > cna > x_generator > engine Vulnogram 0.2.0
containers > adp > 0 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 0 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseScore 7.5
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseSeverity HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
containers > adp > 0 > metrics > 0 > cvssV3_1 > integrityImpact NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > adp > 0 > metrics > 0 > cvssV3_1 > availabilityImpact NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 0 > metrics > 1 > other > type ssvc
containers > adp > 0 > metrics > 1 > other > content > id CVE-2026-34486
containers > adp > 0 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 1 > other > content > options > 1 > Automatable yes
containers > adp > 0 > metrics > 1 > other > content > options > 2 > Technical Impact partial
containers > adp > 0 > metrics > 1 > other > content > version 2.0.3
containers > adp > 0 > metrics > 1 > other > content > timestamp 2026-08-04T17:42:15.722474Z
containers > adp > 0 > metrics > 2 > other > type kev
containers > adp > 0 > metrics > 2 > other > content > dateAdded 2026-08-04
containers > adp > 0 > metrics > 2 > other > content > reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486
containers > adp > 0 > references > 0 > url https://socradar.io/blog/snowlight-government-chinese-campaign/
containers > adp > 0 > references > 0 > tags > 0 third-party-advisory
containers > adp > 0 > references > 1 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486
containers > adp > 0 > references > 1 > tags > 0 government-resource
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-08-04T19:58:24.191Z
containers > adp > 0 > timeline > 0 > time 2026-08-04T00:00:00.000Z
containers > adp > 0 > timeline > 0 > lang en
containers > adp > 0 > timeline > 0 > value CVE-2026-34486 added to CISA KEV
containers > adp > 1 > providerMetadata > orgId af854a3a-2127-422b-91ae-364da2661108
containers > adp > 1 > providerMetadata > shortName CVE
containers > adp > 1 > providerMetadata > dateUpdated 2026-05-26T18:16:14.258Z
containers > adp > 1 > references > 0 > url https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat
containers > adp > 1 > references > 1 > url https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat
containers > adp > 1 > title CVE Program Container
containers > adp > 1 > x_generator > engine ADPogram 0.0.1
containers > adp > 2 > affected > 0 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 0 > cpes > 0 cpe:/o:redhat:enterprise_linux:10.2
containers > adp > 2 > affected > 0 > defaultStatus affected
containers > adp > 2 > affected > 0 > packageName tomcat
containers > adp > 2 > affected > 0 > product Red Hat Enterprise Linux 10
containers > adp > 2 > affected > 0 > vendor Red Hat
containers > adp > 2 > affected > 0 > versions > 0 > lessThan *
containers > adp > 2 > affected > 0 > versions > 0 > status unaffected
containers > adp > 2 > affected > 0 > versions > 0 > version 1:10.1.49-3.el10_2
containers > adp > 2 > affected > 0 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 1 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 1 > cpes > 0 cpe:/o:redhat:enterprise_linux:10.2
containers > adp > 2 > affected > 1 > defaultStatus affected
containers > adp > 2 > affected > 1 > packageName tomcat9
containers > adp > 2 > affected > 1 > product Red Hat Enterprise Linux 10
containers > adp > 2 > affected > 1 > vendor Red Hat
containers > adp > 2 > affected > 1 > versions > 0 > lessThan *
containers > adp > 2 > affected > 1 > versions > 0 > status unaffected
containers > adp > 2 > affected > 1 > versions > 0 > version 1:9.0.117-2.el10_2
containers > adp > 2 > affected > 1 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 2 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 2 > cpes > 0 cpe:/o:redhat:enterprise_linux_eus:10.0
containers > adp > 2 > affected > 2 > defaultStatus affected
containers > adp > 2 > affected > 2 > packageName tomcat
containers > adp > 2 > affected > 2 > product Red Hat Enterprise Linux 10.0 Extended Update Support
containers > adp > 2 > affected > 2 > vendor Red Hat
containers > adp > 2 > affected > 2 > versions > 0 > lessThan *
containers > adp > 2 > affected > 2 > versions > 0 > status unaffected
containers > adp > 2 > affected > 2 > versions > 0 > version 1:10.1.36-2.el10_0
containers > adp > 2 > affected > 2 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 3 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 3 > cpes > 0 cpe:/o:redhat:enterprise_linux_eus:10.0
containers > adp > 2 > affected > 3 > defaultStatus affected
containers > adp > 2 > affected > 3 > packageName tomcat9
containers > adp > 2 > affected > 3 > product Red Hat Enterprise Linux 10.0 Extended Update Support
containers > adp > 2 > affected > 3 > vendor Red Hat
containers > adp > 2 > affected > 3 > versions > 0 > lessThan *
containers > adp > 2 > affected > 3 > versions > 0 > status unaffected
containers > adp > 2 > affected > 3 > versions > 0 > version 1:9.0.87-6.el10_0
containers > adp > 2 > affected > 3 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 4 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 4 > cpes > 0 cpe:/o:redhat:rhel_els:7
containers > adp > 2 > affected > 4 > defaultStatus affected
containers > adp > 2 > affected > 4 > packageName tomcat
containers > adp > 2 > affected > 4 > product Red Hat Enterprise Linux 7 Extended Lifecycle Support
containers > adp > 2 > affected > 4 > vendor Red Hat
containers > adp > 2 > affected > 4 > versions > 0 > lessThan *
containers > adp > 2 > affected > 4 > versions > 0 > status unaffected
containers > adp > 2 > affected > 4 > versions > 0 > version 0:7.0.76-18.el7_9
containers > adp > 2 > affected > 4 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 5 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 5 > cpes > 0 cpe:/a:redhat:enterprise_linux:8
containers > adp > 2 > affected > 5 > defaultStatus affected
containers > adp > 2 > affected > 5 > packageName tomcat
containers > adp > 2 > affected > 5 > product Red Hat Enterprise Linux 8
containers > adp > 2 > affected > 5 > vendor Red Hat
containers > adp > 2 > affected > 5 > versions > 0 > lessThan *
containers > adp > 2 > affected > 5 > versions > 0 > status unaffected
containers > adp > 2 > affected > 5 > versions > 0 > version 1:9.0.87-2.el8_10
containers > adp > 2 > affected > 5 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 6 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 6 > cpes > 0 cpe:/a:redhat:rhel_tus:8.8
containers > adp > 2 > affected > 6 > defaultStatus affected
containers > adp > 2 > affected > 6 > packageName tomcat
containers > adp > 2 > affected > 6 > product Red Hat Enterprise Linux 8.8 Telecommunications Update Service
containers > adp > 2 > affected > 6 > vendor Red Hat
containers > adp > 2 > affected > 6 > versions > 0 > lessThan *
containers > adp > 2 > affected > 6 > versions > 0 > status unaffected
containers > adp > 2 > affected > 6 > versions > 0 > version 1:9.0.87-2.el8_8
containers > adp > 2 > affected > 6 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 7 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 7 > cpes > 0 cpe:/a:redhat:rhel_e4s:8.8
containers > adp > 2 > affected > 7 > defaultStatus affected
containers > adp > 2 > affected > 7 > packageName tomcat
containers > adp > 2 > affected > 7 > product Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
containers > adp > 2 > affected > 7 > vendor Red Hat
containers > adp > 2 > affected > 7 > versions > 0 > lessThan *
containers > adp > 2 > affected > 7 > versions > 0 > status unaffected
containers > adp > 2 > affected > 7 > versions > 0 > version 1:9.0.87-2.el8_8
containers > adp > 2 > affected > 7 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 8 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 8 > cpes > 0 cpe:/a:redhat:enterprise_linux:9
containers > adp > 2 > affected > 8 > defaultStatus affected
containers > adp > 2 > affected > 8 > packageName tomcat
containers > adp > 2 > affected > 8 > product Red Hat Enterprise Linux 9
containers > adp > 2 > affected > 8 > vendor Red Hat
containers > adp > 2 > affected > 8 > versions > 0 > lessThan *
containers > adp > 2 > affected > 8 > versions > 0 > status unaffected
containers > adp > 2 > affected > 8 > versions > 0 > version 1:9.0.117-2.el9_8
containers > adp > 2 > affected > 8 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 9 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 9 > cpes > 0 cpe:/a:redhat:rhel_e4s:9.2
containers > adp > 2 > affected > 9 > defaultStatus affected
containers > adp > 2 > affected > 9 > packageName tomcat
containers > adp > 2 > affected > 9 > product Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
containers > adp > 2 > affected > 9 > vendor Red Hat
containers > adp > 2 > affected > 9 > versions > 0 > lessThan *
containers > adp > 2 > affected > 9 > versions > 0 > status unaffected
containers > adp > 2 > affected > 9 > versions > 0 > version 1:9.0.87-2.el9_2
containers > adp > 2 > affected > 9 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 10 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 10 > cpes > 0 cpe:/a:redhat:rhel_e4s:9.4
containers > adp > 2 > affected > 10 > defaultStatus affected
containers > adp > 2 > affected > 10 > packageName tomcat
containers > adp > 2 > affected > 10 > product Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
containers > adp > 2 > affected > 10 > vendor Red Hat
containers > adp > 2 > affected > 10 > versions > 0 > lessThan *
containers > adp > 2 > affected > 10 > versions > 0 > status unaffected
containers > adp > 2 > affected > 10 > versions > 0 > version 1:9.0.87-2.el9_4
containers > adp > 2 > affected > 10 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 11 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 11 > cpes > 0 cpe:/a:redhat:rhel_eus:9.6
containers > adp > 2 > affected > 11 > defaultStatus affected
containers > adp > 2 > affected > 11 > packageName tomcat
containers > adp > 2 > affected > 11 > product Red Hat Enterprise Linux 9.6 Extended Update Support
containers > adp > 2 > affected > 11 > vendor Red Hat
containers > adp > 2 > affected > 11 > versions > 0 > lessThan *
containers > adp > 2 > affected > 11 > versions > 0 > status unaffected
containers > adp > 2 > affected > 11 > versions > 0 > version 1:9.0.87-4.el9_6
containers > adp > 2 > affected > 11 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 12 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 12 > cpes > 0 cpe:/a:redhat:jboss_enterprise_web_server:7.0
containers > adp > 2 > affected > 12 > defaultStatus unaffected
containers > adp > 2 > affected > 12 > packageName tomcat
containers > adp > 2 > affected > 12 > product Red Hat JBoss Web Server 7.0.0
containers > adp > 2 > affected > 12 > vendor Red Hat
containers > adp > 2 > affected > 13 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 13 > cpes > 0 cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10
containers > adp > 2 > affected > 13 > defaultStatus affected
containers > adp > 2 > affected > 13 > packageName jws7-tomcat
containers > adp > 2 > affected > 13 > product Red Hat JBoss Web Server 7.0 on RHEL 10
containers > adp > 2 > affected > 13 > vendor Red Hat
containers > adp > 2 > affected > 13 > versions > 0 > lessThan *
containers > adp > 2 > affected > 13 > versions > 0 > status unaffected
containers > adp > 2 > affected > 13 > versions > 0 > version 0:11.0.21-5.redhat_00004.1.el10jws
containers > adp > 2 > affected > 13 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 14 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 14 > cpes > 0 cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8
containers > adp > 2 > affected > 14 > defaultStatus affected
containers > adp > 2 > affected > 14 > packageName jws7-tomcat
containers > adp > 2 > affected > 14 > product Red Hat JBoss Web Server 7.0 on RHEL 8
containers > adp > 2 > affected > 14 > vendor Red Hat
containers > adp > 2 > affected > 14 > versions > 0 > lessThan *
containers > adp > 2 > affected > 14 > versions > 0 > status unaffected
containers > adp > 2 > affected > 14 > versions > 0 > version 0:11.0.21-5.redhat_00004.1.el8jws
containers > adp > 2 > affected > 14 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 15 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 15 > cpes > 0 cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9
containers > adp > 2 > affected > 15 > defaultStatus affected
containers > adp > 2 > affected > 15 > packageName jws7-tomcat
containers > adp > 2 > affected > 15 > product Red Hat JBoss Web Server 7.0 on RHEL 9
containers > adp > 2 > affected > 15 > vendor Red Hat
containers > adp > 2 > affected > 15 > versions > 0 > lessThan *
containers > adp > 2 > affected > 15 > versions > 0 > status unaffected
containers > adp > 2 > affected > 15 > versions > 0 > version 0:11.0.21-5.redhat_00004.1.el9jws
containers > adp > 2 > affected > 15 > versions > 0 > versionType rpm
containers > adp > 2 > affected > 16 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 16 > cpes > 0 cpe:/o:redhat:enterprise_linux:6
containers > adp > 2 > affected > 16 > defaultStatus unknown
containers > adp > 2 > affected > 16 > packageName tomcat6
containers > adp > 2 > affected > 16 > product Red Hat Enterprise Linux 6
containers > adp > 2 > affected > 16 > vendor Red Hat
containers > adp > 2 > affected > 17 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 17 > cpes > 0 cpe:/o:redhat:enterprise_linux:8
containers > adp > 2 > affected > 17 > defaultStatus affected
containers > adp > 2 > affected > 17 > packageName pki-deps:10.6/pki-servlet-engine
containers > adp > 2 > affected > 17 > product Red Hat Enterprise Linux 8
containers > adp > 2 > affected > 17 > vendor Red Hat
containers > adp > 2 > affected > 18 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 18 > cpes > 0 cpe:/o:redhat:enterprise_linux:9
containers > adp > 2 > affected > 18 > defaultStatus affected
containers > adp > 2 > affected > 18 > packageName pki-servlet-engine
containers > adp > 2 > affected > 18 > product Red Hat Enterprise Linux 9
containers > adp > 2 > affected > 18 > vendor Red Hat
containers > adp > 2 > affected > 19 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 19 > cpes > 0 cpe:/a:redhat:jboss_enterprise_web_server:5
containers > adp > 2 > affected > 19 > defaultStatus affected
containers > adp > 2 > affected > 19 > packageName tomcat
containers > adp > 2 > affected > 19 > product Red Hat JBoss Web Server 5
containers > adp > 2 > affected > 19 > vendor Red Hat
containers > adp > 2 > affected > 20 > collectionURL https://access.redhat.com/downloads/content/package-browser/
containers > adp > 2 > affected > 20 > cpes > 0 cpe:/a:redhat:jboss_enterprise_web_server:6
containers > adp > 2 > affected > 20 > defaultStatus affected
containers > adp > 2 > affected > 20 > packageName tomcat
containers > adp > 2 > affected > 20 > product Red Hat JBoss Web Server 6
containers > adp > 2 > affected > 20 > vendor Red Hat
containers > adp > 2 > datePublic 2026-04-09T19:35:35.994Z
containers > adp > 2 > descriptions > 0 > lang en
containers > adp > 2 > descriptions > 0 > value A flaw was found in Apache Tomcat. This vulnerability, categorized as Missing Encryption of Sensitive Data, arises from a bypass in the EncryptInterceptor, a component designed to ensure data encryption. This bypass, introduced as a fix for CVE-2026-29146, allows sensitive data to remain unencrypted, potentially leading to information disclosure.
containers > adp > 2 > metrics > 0 > other > content > namespace https://access.redhat.com/security/updates/classification/
containers > adp > 2 > metrics > 0 > other > content > value Important
containers > adp > 2 > metrics > 0 > other > type Red Hat severity rating
containers > adp > 2 > metrics > 1 > cvssV3_1 > attackComplexity LOW
containers > adp > 2 > metrics > 1 > cvssV3_1 > attackVector NETWORK
containers > adp > 2 > metrics > 1 > cvssV3_1 > availabilityImpact NONE
containers > adp > 2 > metrics > 1 > cvssV3_1 > baseScore 7.5
containers > adp > 2 > metrics > 1 > cvssV3_1 > baseSeverity HIGH
containers > adp > 2 > metrics > 1 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 2 > metrics > 1 > cvssV3_1 > integrityImpact NONE
containers > adp > 2 > metrics > 1 > cvssV3_1 > privilegesRequired NONE
containers > adp > 2 > metrics > 1 > cvssV3_1 > scope UNCHANGED
containers > adp > 2 > metrics > 1 > cvssV3_1 > userInteraction NONE
containers > adp > 2 > metrics > 1 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
containers > adp > 2 > metrics > 1 > cvssV3_1 > version 3.1
containers > adp > 2 > metrics > 1 > format CVSS
containers > adp > 2 > problemTypes > 0 > descriptions > 0 > cweId CWE-807
containers > adp > 2 > problemTypes > 0 > descriptions > 0 > description Reliance on Untrusted Inputs in a Security Decision
containers > adp > 2 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 2 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 2 > references > 0 > tags > 0 vdb-entry
containers > adp > 2 > references > 0 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 0 > url https://access.redhat.com/security/cve/CVE-2026-34486
containers > adp > 2 > references > 1 > name RHBZ#2457027
containers > adp > 2 > references > 1 > tags > 0 issue-tracking
containers > adp > 2 > references > 1 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 1 > url https://bugzilla.redhat.com/show_bug.cgi?id=2457027
containers > adp > 2 > references > 2 > tags > 0 x_sadp-csaf-vex
containers > adp > 2 > references > 2 > url https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json
containers > adp > 2 > references > 3 > tags > 0 vendor-advisory
containers > adp > 2 > references > 3 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 3 > url https://access.redhat.com/errata/RHSA-2026:39188
containers > adp > 2 > references > 4 > tags > 0 vendor-advisory
containers > adp > 2 > references > 4 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 4 > url https://access.redhat.com/errata/RHSA-2026:38505
containers > adp > 2 > references > 5 > tags > 0 vendor-advisory
containers > adp > 2 > references > 5 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 5 > url https://access.redhat.com/errata/RHSA-2026:36787
containers > adp > 2 > references > 6 > tags > 0 vendor-advisory
containers > adp > 2 > references > 6 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 6 > url https://access.redhat.com/errata/RHSA-2026:36789
containers > adp > 2 > references > 7 > tags > 0 vendor-advisory
containers > adp > 2 > references > 7 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 7 > url https://access.redhat.com/errata/RHSA-2026:36788
containers > adp > 2 > references > 8 > tags > 0 vendor-advisory
containers > adp > 2 > references > 8 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 8 > url https://access.redhat.com/errata/RHSA-2026:36790
containers > adp > 2 > references > 9 > tags > 0 vendor-advisory
containers > adp > 2 > references > 9 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 9 > url https://access.redhat.com/errata/RHSA-2026:37137
containers > adp > 2 > references > 10 > tags > 0 vendor-advisory
containers > adp > 2 > references > 10 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 10 > url https://access.redhat.com/errata/RHSA-2026:37136
containers > adp > 2 > references > 11 > tags > 0 vendor-advisory
containers > adp > 2 > references > 11 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 11 > url https://access.redhat.com/errata/RHSA-2026:36878
containers > adp > 2 > references > 12 > tags > 0 vendor-advisory
containers > adp > 2 > references > 12 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 12 > url https://access.redhat.com/errata/RHSA-2026:36876
containers > adp > 2 > references > 13 > tags > 0 vendor-advisory
containers > adp > 2 > references > 13 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 13 > url https://access.redhat.com/errata/RHSA-2026:36877
containers > adp > 2 > references > 14 > tags > 0 vendor-advisory
containers > adp > 2 > references > 14 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 14 > url https://access.redhat.com/errata/RHSA-2026:36879
containers > adp > 2 > references > 15 > tags > 0 vendor-advisory
containers > adp > 2 > references > 15 > tags > 1 x_refsource_REDHAT
containers > adp > 2 > references > 15 > url https://access.redhat.com/errata/RHSA-2026:39189
containers > adp > 2 > solutions > 0 > lang en
containers > adp > 2 > solutions > 0 > value RHSA-2026:39188: Red Hat JBoss Web Server 7.0 on RHEL 10, Red Hat JBoss Web Server 7.0 on RHEL 8, Red Hat JBoss Web Server 7.0 on RHEL 9
containers > adp > 2 > solutions > 1 > lang en
containers > adp > 2 > solutions > 1 > value RHSA-2026:38505: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS)
containers > adp > 2 > solutions > 2 > lang en
containers > adp > 2 > solutions > 2 > value RHSA-2026:36787: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
containers > adp > 2 > solutions > 3 > lang en
containers > adp > 2 > solutions > 3 > value RHSA-2026:36789: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
containers > adp > 2 > solutions > 4 > lang en
containers > adp > 2 > solutions > 4 > value RHSA-2026:36788: Red Hat Enterprise Linux AppStream (v. 10)
containers > adp > 2 > solutions > 5 > lang en
containers > adp > 2 > solutions > 5 > value RHSA-2026:36790: Red Hat Enterprise Linux AppStream (v. 10)
containers > adp > 2 > solutions > 6 > lang en
containers > adp > 2 > solutions > 6 > value RHSA-2026:37137: Red Hat Enterprise Linux AppStream (v. 8)
containers > adp > 2 > solutions > 7 > lang en
containers > adp > 2 > solutions > 7 > value RHSA-2026:37136: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8)
containers > adp > 2 > solutions > 8 > lang en
containers > adp > 2 > solutions > 8 > value RHSA-2026:36878: Red Hat Enterprise Linux AppStream E4S (v.9.2)
containers > adp > 2 > solutions > 9 > lang en
containers > adp > 2 > solutions > 9 > value RHSA-2026:36876: Red Hat Enterprise Linux AppStream E4S (v.9.4)
containers > adp > 2 > solutions > 10 > lang en
containers > adp > 2 > solutions > 10 > value RHSA-2026:36877: Red Hat Enterprise Linux AppStream EUS (v.9.6)
containers > adp > 2 > solutions > 11 > lang en
containers > adp > 2 > solutions > 11 > value RHSA-2026:36879: Red Hat Enterprise Linux AppStream (v. 9)
containers > adp > 2 > solutions > 12 > lang en
containers > adp > 2 > solutions > 12 > value RHSA-2026:39189: Red Hat JBoss Web Server 7.0.0
containers > adp > 2 > timeline > 0 > lang en
containers > adp > 2 > timeline > 0 > time 2026-04-09T20:01:26.022Z
containers > adp > 2 > timeline > 0 > value Reported to Red Hat.
containers > adp > 2 > timeline > 1 > lang en
containers > adp > 2 > timeline > 1 > time 2026-04-09T19:35:35.994Z
containers > adp > 2 > timeline > 1 > value Made public.
containers > adp > 2 > title Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass
containers > adp > 2 > workarounds > 0 > lang en
containers > adp > 2 > workarounds > 0 > value Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
containers > adp > 2 > x_adpType supplier
containers > adp > 2 > x_generator > engine sadp-cli 1.0.0
containers > adp > 2 > providerMetadata > orgId 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
containers > adp > 2 > providerMetadata > shortName redhat-SADP
containers > adp > 2 > providerMetadata > dateUpdated 2026-07-20T12:05:04.800Z