Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-55957

Apache Tomcat: authentication bypass with JNDIRealm and a GSSAPI authenticated bind

Technology

Apache Tomcat

CVSS Score

7.3 / 10.0

Affected Versions

11.0.0-M1 to 11.0.4; 10.1.0-M1 to 10.1.36; 9.0.0.M1 to 9.0.100; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109

Upstream Fix

11.0.5; 10.1.39; 9.0.102 (the CVE record names 10.1.37 and 9.0.101)

Published

June 29, 2026

OSSeva Coverage

Fixed upstream

Description

When the JNDIRealm was configured to authenticate binds using GSSAPI, an attacker could authenticate without providing the correct password. Rated Important by the Tomcat security team. The fix shipped in March 2025, and the issue was made public on 29 June 2026. The Tomcat security pages list it as fixed in 11.0.5, 10.1.39 and 9.0.102.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.4; 10.1.0-M1 to 10.1.36; 9.0.0.M1 to 9.0.100; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109, you need this patch. Book a discovery call to get covered.