Apache · Apache Tomcat · CVE-2026-76183
**Name of the Vulnerable Software and Affected Versions**
Apache Tomcat versions 11.0.0-M1 through 11.0.25
Apache Tomcat versions 10.1.0-M1 through 10.1.59
Apache Tomcat versions 9.0.0.M1 through 9.0.121
Apache Tomcat versions 8.5.0 through 8.5.100
Apache Tomcat versions 7.0.43 through 7.0.109
**Description**
An authentication bypass exists when accessing WebSocket endpoints via an alternate name. This flaw allows security constraints to be bypassed, enabling unauthorized access to protected WebSocket endpoints.
**Recommendations**
Upgrade to version 11.0.26
Upgrade to version 10.1.60
Upgrade to version 9.0.122
At the moment, there is no information about a newer version that contains a fix for this vulnerability for versions 8.5.x and 7.0.x.