Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Apache Tomcat has a flaw where sensitive data encryption can be bypassed due to an incomplete fix. This means attackers could intercept and read private information that should have been protected.
CVE-2026-34486 involves a bypass of the EncryptInterceptor mechanism in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116. The vulnerability stems from an insufficient fix to CVE-2026-29146, allowing attackers to circumvent encryption protections for sensitive data in transit. Exploitation requires network-level access to intercepted communications, with impact ranging from confidentiality breach of encrypted payloads.