CVE-2026-34486
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Description
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Description as published by the source, in English.
Key facts
- Published
- 2026-04-09
- Last modified
- 2026-08-10
- Assigned by
- security@apache.org
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N- Scored by
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Probability of exploitation
-
42.6 %
higher than 99 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-08-04, with a remediation deadline of 2026-08-07 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Apache | Tomcat | 10.1.53 | Affected |
| Apache | Tomcat | 11.0.20 | Affected |
| Apache | Tomcat | 9.0.116 | Affected |
| Redhat | Enterprise Linux | 10.0 | Affected |
| Redhat | Enterprise Linux | 8.0 | Affected |
| Redhat | Enterprise Linux | 9.0 | Affected |
| Redhat | Enterprise Linux Els | 7.0 | Affected |
| Redhat | Enterprise Linux Eus | 10.0 | Affected |
| Redhat | Enterprise Linux Tus | 8.8 | Affected |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.8 | Affected |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.2 | Affected |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.4 | Affected |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.6 | Affected |
| Redhat | Jboss Web Server | 7.0.0 | Affected |
Weakness type
-
CWE-311: Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
-
CWE-807: Reliance on Untrusted Inputs in a Security Decision
The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.
- T1005: Data from Local System
- T1040: Network Sniffing
- T1056.004: Credential API Hooking
- T1111: Multi-Factor Authentication Interception
- T1539: Steal Web Session Cookie
- T1552.004: Private Keys
References
- https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
- https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomc…
- https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tom…
- https://access.redhat.com/errata/RHSA-2026:36787
- https://access.redhat.com/errata/RHSA-2026:36788
- https://access.redhat.com/errata/RHSA-2026:36789
- https://access.redhat.com/errata/RHSA-2026:36790
- https://access.redhat.com/errata/RHSA-2026:36876
- https://access.redhat.com/errata/RHSA-2026:36877
- https://access.redhat.com/errata/RHSA-2026:36878
- https://access.redhat.com/errata/RHSA-2026:36879
- https://access.redhat.com/errata/RHSA-2026:37136
- https://access.redhat.com/errata/RHSA-2026:37137
- https://access.redhat.com/errata/RHSA-2026:38505
- https://access.redhat.com/errata/RHSA-2026:39188
- https://access.redhat.com/errata/RHSA-2026:39189
- https://access.redhat.com/security/cve/CVE-2026-34486
- https://bugzilla.redhat.com/show_bug.cgi?id=2457027
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json
- https://socradar.io/blog/snowlight-government-chinese-campaign/
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.