Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-76183: Apache Tomcat WebSocket authentication can be bypassed

CVE-2026-76183 · published 1 day ago
Summary

Apache Tomcat versions up through 11.0.25, 10.1.59, 9.0.121 and older releases allow attackers to skip login checks on WebSocket connections. This could let unauthorized users interact with your applications. Upgrade to Tomcat 11.0.26, 10.1.60, or 9.0.122 (or later) to close the gap.

What to do
  • Update debian tomcat9 to version 9.0.70-2.
Affected software
Ecosystem VendorProductAffected versions
– apache software foundation apache tomcat <= 11.0.25
Debian:13 debian tomcat11 All versions
Debian:12 debian tomcat10 All versions
Debian:12 debian tomcat9 < 9.0.70-2
Fix: upgrade to 9.0.70-2
Ubuntu:Pro:14.04:LTS canonical tomcat6 All versions
Ubuntu:Pro:14.04:LTS canonical tomcat7 All versions
Ubuntu:Pro:16.04:LTS canonical tomcat8 All versions
Ubuntu:Pro:18.04:LTS canonical tomcat9 All versions
Ubuntu:24.04:LTS canonical tomcat10 All versions
Ubuntu:26.04:LTS canonical tomcat11 All versions
Original advisory text
DEBIAN-CVE-2026-76183
Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-289Authentication Bypass by Alternate Name
Timeline
Published24 Sep 2026
Updated25 Sep 2026
First seen23 Sep 2026
Track software like this
Free during beta