Apache · Apache Tomcat · CVE-2026-55957
**Name of the Vulnerable Software and Affected Versions**
Apache Tomcat versions 11.0.0-M1 through 11.0.4
Apache Tomcat versions 10.1.0-M1 through 10.1.36
Apache Tomcat versions 9.0.0.M1 through 9.0.100
Apache Tomcat versions 8.5.0 through 8.5.100
Apache Tomcat versions 7.0.0 through 7.0.109
**Description**
A missing critical step in the authentication process occurs when the `JNDIRealm` is configured to authenticate binds using GSSAPI (Generic Security Services Application Program Interface), a standard for security software to provide authentication services. This flaw allows attackers to authenticate successfully without providing the correct password.
**Recommendations**
Upgrade to version 11.0.5
Upgrade to version 10.1.37
Upgrade to version 9.0.101