CVE-2026-34486
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
- Affected products
- Apache Tomcat, Rocky Linux
- Apache Tomcat
- = 9.0.116, 10.1.53, 11.0.20
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 98.6% (100th percentile)
- Weakness
- CWE-807, CWE-311
- NVD status
- Analyzed
- Published
- 2026-04-09
CVE-2026-34486 at NVD
15 known exploits for CVE-2026-34486
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization
cve-2026-34486-tomcat_encrypt_bypass_reproduction
CVE-2026-34486
ASIS-CTF-Quals-2026
CVE-2026-34486
CVE-2026-34486-poc
tomcat-cve-2026-34486
Exploit for Reliance on Untrusted Inputs in a Security Decision in Apache Tomcat
Exploit for Reliance on Untrusted Inputs in a Security Decision in Apache Tomcat
Exploit for Missing Encryption of Sensitive Data in Apache Tomcat
Exploit for Missing Encryption of Sensitive Data in Apache Tomcat
Exploit for Missing Encryption of Sensitive Data in Apache Tomcat
Exploit for Missing Encryption of Sensitive Data in Apache Tomcat
Exploit for Missing Encryption of Sensitive Data in Apache Tomcat
CVE-2026-34486