Two Apache Tomcat flaws can put security controls out of action

Apache has published details of two vulnerabilities in Apache Tomcat. The more severe, CVE-2026-55957, can allow authentication bypass. The second, CVE-2026-55956, can cause HTTP methods or method omissions in security constraints for the default servlet to be ignored, so restrictions are not enforced as expected. There are no known reports of active exploitation or publicly available exploit code.

What this means for your organisation

Tomcat sits underneath a great many business systems and integrations, often without appearing in the service catalogue. When authentication can be bypassed, the assumption that the application is protected by access control collapses, and logs will not necessarily show anything unusual. The practical difficulty is rarely the patching itself, but knowing where Tomcat actually runs.

Berigo recommends

  • Map which applications run Tomcat, including components delivered by third parties.
  • Update to a fixed version as soon as practicable, and ask suppliers to confirm their packages are updated.
  • Review the security constraints for the default servlet and verify they are enforced as intended.
  • Bring supplier-delivered software components into ongoing vulnerability management.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch