PT-2026-81876 · Apache · Apache Tomcat

·

CVE-2026-65182

·

Published

2026-08-25

·

Updated

2026-09-11

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.24 Apache Tomcat versions 10.1.0-M1 through 10.1.57 Apache Tomcat versions 9.0.0.M1 through 9.0.120 Apache Tomcat versions 8.5.0 through 8.5.100 Apache Tomcat versions 7.0.0 through 7.0.109
Description Improper access control and incorrect authorization allow an unauthenticated attacker to bypass security constraints. This occurs when a security constraint for a longer path is processed before a more restrictive constraint for a shorter sub-path, leading the system to evaluate constraints incorrectly and grant access to protected resources.
Recommendations Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.24 to version 11.0.25. Upgrade Apache Tomcat versions 10.1.0-M1 through 10.1.57 to version 10.1.58. Upgrade Apache Tomcat versions 9.0.0.M1 through 9.0.120 to version 9.0.121. At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 8.5.0 through 8.5.100. At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 7.0.0 through 7.0.109.

Exploit

Fix

DoS

Improper Access Control

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-TOMCAT-2026-65182
CVE-2026-65182
GHSA-GCX9-497G-6CP6
OPENSUSE-SU-2026:11759-1
OPENSUSE-SU-2026:11760-1
OPENSUSE-SU-2026:11761-1
OPENSUSE-SU-2026:21810-1
OPENSUSE-SU-2026:21811-1
RHSA-2026:56039

Affected Products

Apache Tomcat