Description
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- apache / Tomcat9.0.116 – 9.0.116
- apache / Tomcat10.1.53 – 10.1.53
- apache / Tomcat11.0.20 – 11.0.20
- Apache Software Foundation / Apache Tomcat11.0.20 – 11.0.20
- Apache Software Foundation / Apache Tomcat10.1.53 – 10.1.53
- Apache Software Foundation / Apache Tomcat9.0.116 – 9.0.116
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / enterprise_linux_els7.0 – 7.0
- RedHat / enterprise_linux_eus10.0 – 10.0
- RedHat / enterprise_linux_tus8.8 – 8.8
- RedHat / enterprise_linux_update_services_for_sap_solutions9.4 – 9.4
- RedHat / enterprise_linux_update_services_for_sap_solutions9.6 – 9.6
- RedHat / enterprise_linux_update_services_for_sap_solutions8.8 – 8.8
- RedHat / enterprise_linux_update_services_for_sap_solutions9.2 – 9.2
- RedHat / jboss_web_server7.0.0 – 7.0.0
Exploits & proofs of concept
- nucleiApache Tomcat Tribes EncryptInterceptor Bypass - Remote Code Executionby DhiyaneshDk
References
Updated 24m ago · 8 sources