CVE-2026-34486 CRITICAL

Apache Tomcat Vulnerability
Generated: 10 Oct 2026 19:30 • CVE Threat Intelligence

Description

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

9.8
CVSS CRITICAL

Details

Published
04 Aug 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
Apache
Product
Tomcat
Fix Version
Vendor Patch / Mitigation Available

References