CVE-2026-55957
Apache Tomcat: authentication bypass with JNDIRealm and a GSSAPI authenticated bind
Technology
Apache Tomcat
CVSS Score
7.3 / 10.0
Affected Versions
11.0.0-M1 to 11.0.4; 10.1.0-M1 to 10.1.36; 9.0.0.M1 to 9.0.100; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109
Upstream Fix
11.0.5; 10.1.39; 9.0.102 (the CVE record names 10.1.37 and 9.0.101)
Published
June 29, 2026
OSSeva Coverage
Fixed upstream
Description
When the JNDIRealm was configured to authenticate binds using GSSAPI, an attacker could authenticate without providing the correct password. Rated Important by the Tomcat security team. The fix shipped in March 2025, and the issue was made public on 29 June 2026. The Tomcat security pages list it as fixed in 11.0.5, 10.1.39 and 9.0.102.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.4; 10.1.0-M1 to 10.1.36; 9.0.0.M1 to 9.0.100; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109, you need this patch. Book a discovery call to get covered.