Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-86248: Apache Tomcat client certificate check can be bypassed

CVE-2026-86248 · published 1 day ago
Summary

Certain versions of Apache Tomcat may not correctly reject invalid client certificates when a stricter setting is used. This could let unauthorized users gain access to services that rely on certificate authentication. Upgrade to Tomcat 9.0.122, 10.1.60, or 11.0.26, or apply the vendor's supplied patch, to resolve the issue.

What to do
  • Update debian tomcat9 to version 9.0.70-2.
Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian tomcat10 All versions
– apache software foundation apache tomcat <= 11.0.25
Debian:13 debian tomcat11 All versions
Debian:12 debian tomcat9 < 9.0.70-2
Fix: upgrade to 9.0.70-2
Ubuntu:Pro:14.04:LTS canonical tomcat6 All versions
Ubuntu:Pro:14.04:LTS canonical tomcat7 All versions
Ubuntu:Pro:16.04:LTS canonical tomcat8 All versions
Ubuntu:Pro:18.04:LTS canonical tomcat9 All versions
Ubuntu:24.04:LTS canonical tomcat10 All versions
Ubuntu:26.04:LTS canonical tomcat11 All versions
Original advisory text
DEBIAN-CVE-2026-86248
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published24 Sep 2026
Updated25 Sep 2026
First seen23 Sep 2026
Track software like this
Free during beta