Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-34486
Apache Tomcat: EncryptInterceptor bypass introduced by the CVE-2026-29146 fix
Technology
Apache Tomcat
CVSS Score
7.5 / 10.0
Affected Versions
11.0.20; 10.1.53; 9.0.116
Upstream Fix
11.0.21; 10.1.54; 9.0.117
Published
April 9, 2026
OSSeva Coverage
Fixed upstream
Description
The fix for CVE-2026-29146 allowed the cluster EncryptInterceptor to be bypassed (missing encryption of sensitive data). Only 11.0.20, 10.1.53 and 9.0.116 are affected. Fixed in 11.0.21, 10.1.54 and 9.0.117. CISA added it to its Known Exploited Vulnerabilities catalog on 4 August 2026.
Is your Apache Tomcat deployment affected?
If you're running 11.0.20; 10.1.53; 9.0.116, you need this patch. Book a discovery call to get covered.