CVE-2026-34486
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Beskrivelse
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Beskrivelsen gjengis slik kilden har publisert den, på engelsk.
Nøkkelfakta
- Publisert
- 2026-04-09
- Sist endret
- 2026-08-10
- Tildelt av
- security@apache.org
- CVSS-vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N- Scoret av
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Sannsynlighet for utnyttelse
-
42.6 %
høyere enn 99 %
av alle kjente sårbarheter
EPSS, neste 30 dager, modell v2026.06.15 - Rettelse finnes
- Ikke registrert hos kildene
Aktivt utnyttet
CISA førte denne sårbarheten inn i katalogen over kjente utnyttede sårbarheter 2026-08-04, med utbedringsfrist 2026-08-07 for amerikanske føderale etater.
Pålagt tiltak: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Berørte produkter
| Leverandør | Produkt | Versjoner | Status |
|---|---|---|---|
| Apache | Tomcat | 10.1.53 | Berørt |
| Apache | Tomcat | 11.0.20 | Berørt |
| Apache | Tomcat | 9.0.116 | Berørt |
| Redhat | Enterprise Linux | 10.0 | Berørt |
| Redhat | Enterprise Linux | 8.0 | Berørt |
| Redhat | Enterprise Linux | 9.0 | Berørt |
| Redhat | Enterprise Linux Els | 7.0 | Berørt |
| Redhat | Enterprise Linux Eus | 10.0 | Berørt |
| Redhat | Enterprise Linux Tus | 8.8 | Berørt |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 8.8 | Berørt |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.2 | Berørt |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.4 | Berørt |
| Redhat | Enterprise Linux Update Services For Sap Solutions | 9.6 | Berørt |
| Redhat | Jboss Web Server | 7.0.0 | Berørt |
Svakhetstype
-
CWE-311: Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
-
CWE-807: Reliance on Untrusted Inputs in a Security Decision
The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
Angrepsteknikker
Utledet gjennom svakhetstypen: CVE til CWE til CAPEC til ATT&CK. Dette viser hvilke teknikker svakhetsklassen historisk brukes til. Det er ikke en påstand om at nettopp denne sårbarheten er utnyttet slik.
- T1005: Data from Local System
- T1040: Network Sniffing
- T1056.004: Credential API Hooking
- T1111: Multi-Factor Authentication Interception
- T1539: Steal Web Session Cookie
- T1552.004: Private Keys
Referanser
- https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
- https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomc…
- https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tom…
- https://access.redhat.com/errata/RHSA-2026:36787
- https://access.redhat.com/errata/RHSA-2026:36788
- https://access.redhat.com/errata/RHSA-2026:36789
- https://access.redhat.com/errata/RHSA-2026:36790
- https://access.redhat.com/errata/RHSA-2026:36876
- https://access.redhat.com/errata/RHSA-2026:36877
- https://access.redhat.com/errata/RHSA-2026:36878
- https://access.redhat.com/errata/RHSA-2026:36879
- https://access.redhat.com/errata/RHSA-2026:37136
- https://access.redhat.com/errata/RHSA-2026:37137
- https://access.redhat.com/errata/RHSA-2026:38505
- https://access.redhat.com/errata/RHSA-2026:39188
- https://access.redhat.com/errata/RHSA-2026:39189
- https://access.redhat.com/security/cve/CVE-2026-34486
- https://bugzilla.redhat.com/show_bug.cgi?id=2457027
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json
- https://socradar.io/blog/snowlight-government-chinese-campaign/
Berører dette dere?
En sårbarhet betyr bare noe hvis dere kjører produktet, i en berørt versjon, et sted en angriper kommer til.