Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-76183: Apache Tomcat WebSocket authentication can be bypassed
CVE-2026-76183 · published 1 day ago
Summary
Apache Tomcat versions up through 11.0.25, 10.1.59, 9.0.121 and older releases allow attackers to skip login checks on WebSocket connections. This could let unauthorized users interact with your applications. Upgrade to Tomcat 11.0.26, 10.1.60, or 9.0.122 (or later) to close the gap.
What to do
- Update debian tomcat9 to version 9.0.70-2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | apache software foundation | apache tomcat | <= 11.0.25 |
| Debian:13 | debian | tomcat11 | All versions |
| Debian:12 | debian | tomcat10 | All versions |
| Debian:12 | debian | tomcat9 |
< 9.0.70-2 Fix: upgrade to 9.0.70-2
|
| Ubuntu:Pro:14.04:LTS | canonical | tomcat6 | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | tomcat7 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | tomcat8 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | tomcat9 | All versions |
| Ubuntu:24.04:LTS | canonical | tomcat10 | All versions |
| Ubuntu:26.04:LTS | canonical | tomcat11 | All versions |
Original advisory text
DEBIAN-CVE-2026-76183
Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
References
- https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp Third Party Advisory
- http://www.openwall.com/lists/oss-security/2026/09/23/21 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-76183 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-76183 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-76183 Third Party Advisory
- https://github.com/apache/tomcat/commit/e182d86b7d4cc19ec4c24c38f37acc004404fe8e Third Party Advisory
- https://github.com/apache/tomcat/commit/5b48790abd13d94c2bd351027a39a671916b5ddf Third Party Advisory
- https://github.com/apache/tomcat/commit/a93a60a33f4cc202542eb6a0b87b7142d7db311c Third Party Advisory
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-289Authentication Bypass by Alternate Name
Timeline
Published24 Sep 2026
Updated25 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-76183 · NVD
CVE-2026-76183 · MITRE
DEBIAN-CVE-2026-76183 · OSV
UBUNTU-CVE-2026-76183 · OSV
Track software like this
Free during beta