Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-86248: Apache Tomcat client certificate check can be bypassed
CVE-2026-86248 · published 1 day ago
Summary
Certain versions of Apache Tomcat may not correctly reject invalid client certificates when a stricter setting is used. This could let unauthorized users gain access to services that rely on certificate authentication. Upgrade to Tomcat 9.0.122, 10.1.60, or 11.0.26, or apply the vendor's supplied patch, to resolve the issue.
What to do
- Update debian tomcat9 to version 9.0.70-2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | tomcat10 | All versions |
| – | apache software foundation | apache tomcat | <= 11.0.25 |
| Debian:13 | debian | tomcat11 | All versions |
| Debian:12 | debian | tomcat9 |
< 9.0.70-2 Fix: upgrade to 9.0.70-2
|
| Ubuntu:Pro:14.04:LTS | canonical | tomcat6 | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | tomcat7 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | tomcat8 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | tomcat9 | All versions |
| Ubuntu:24.04:LTS | canonical | tomcat10 | All versions |
| Ubuntu:26.04:LTS | canonical | tomcat11 | All versions |
Original advisory text
DEBIAN-CVE-2026-86248
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
References
- https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-86248 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-86248 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-86248 Third Party Advisory
- https://github.com/apache/tomcat/commit/9aab76056e7470bcc8ca9a20b33b6558b1046da2 Third Party Advisory
- https://github.com/apache/tomcat/commit/e5191b1e3292681097503f093b5432451ff5aa83 Third Party Advisory
- https://github.com/apache/tomcat/commit/fc41d82e0e383e4d6e88ad321d245dafdc17d26d Third Party Advisory
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published24 Sep 2026
Updated25 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-86248 · NVD
CVE-2026-86248 · MITRE
DEBIAN-CVE-2026-86248 · OSV
UBUNTU-CVE-2026-86248 · OSV
Track software like this
Free during beta