Apache · Apache Tomcat · CVE-2026-65182
**Name of the Vulnerable Software and Affected Versions**
Apache Tomcat versions 11.0.0-M1 through 11.0.24
Apache Tomcat versions 10.1.0-M1 through 10.1.57
Apache Tomcat versions 9.0.0.M1 through 9.0.120
Apache Tomcat versions 8.5.0 through 8.5.100
Apache Tomcat versions 7.0.0 through 7.0.109
**Description**
Improper access control and incorrect authorization allow an unauthenticated attacker to bypass security constraints. This occurs when a security constraint for a longer path is processed before a more restrictive constraint for a shorter sub-path, leading the system to evaluate constraints incorrectly and grant access to protected resources.
**Recommendations**
Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.24 to version 11.0.25.
Upgrade Apache Tomcat versions 10.1.0-M1 through 10.1.57 to version 10.1.58.
Upgrade Apache Tomcat versions 9.0.0.M1 through 9.0.120 to version 9.0.121.
At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 8.5.0 through 8.5.100.
At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 7.0.0 through 7.0.109.