Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.3epss 2.9%
from disclosure to weapon39 days
Published on NVDJun 29
1st PoC+39d
exploitation probability
2.9%top 14% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
Apache Software Foundation · Apache Tomcatpublic PoCs found — 1
githubgithub.com/mdvpat/CVE-2026-55957-PoC★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.