Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-34486

Apache Tomcat: EncryptInterceptor bypass introduced by the CVE-2026-29146 fix

Technology

Apache Tomcat

CVSS Score

7.5 / 10.0

Affected Versions

11.0.20; 10.1.53; 9.0.116

Upstream Fix

11.0.21; 10.1.54; 9.0.117

Published

April 9, 2026

OSSeva Coverage

Fixed upstream

Description

The fix for CVE-2026-29146 allowed the cluster EncryptInterceptor to be bypassed (missing encryption of sensitive data). Only 11.0.20, 10.1.53 and 9.0.116 are affected. Fixed in 11.0.21, 10.1.54 and 9.0.117. CISA added it to its Known Exploited Vulnerabilities catalog on 4 August 2026.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.20; 10.1.53; 9.0.116, you need this patch. Book a discovery call to get covered.