PT-2026-53745 · Apache+1 · Apache Tomcat+1

·

CVE-2026-55956

·

Published

2026-06-22

·

Updated

2026-09-11

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.22 Apache Tomcat versions 10.1.0-M1 through 10.1.55 Apache Tomcat versions 9.0.0.M1 through 9.0.118 Apache Tomcat versions 8.5.0 through 8.5.100 Apache Tomcat versions 7.0.0 through 7.0.109
Description An improper authorization issue exists where security constraints defined for the default servlet ignore any configured method or method omission. This allows requests to bypass intended security restrictions when they are applied to the default servlet.
Recommendations Upgrade to version 11.0.23 Upgrade to version 10.1.56 Upgrade to version 9.0.119

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11870
BIT-TOMCAT-2026-55956
CVE-2026-55956
OESA-2026-2947
OESA-2026-2948
OESA-2026-2949
OESA-2026-2950
OPENSUSE-SU-2026:11195-1
OPENSUSE-SU-2026:11208-1
OPENSUSE-SU-2026:11209-1
OPENSUSE-SU-2026:21327-1
OPENSUSE-SU-2026:21328-1
OPENSUSE-SU-2026:21329-1
RHSA-2026:43401
SUSE-SU-2026:22646-1
SUSE-SU-2026:22647-1
SUSE-SU-2026:22648-1
SUSE-SU-2026:3087-1
SUSE-SU-2026:3088-1
SUSE-SU-2026:3112-1
SUSE-SU-2026:3167-1

Affected Products

Apache Tomcat
Red Os