Sploitus

Exploit for CVE-2026-34486

kitploit · 2026-08-27

Exploit Code

MARKDOWN10 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-404-SRC-CVE-2026-34486
# CVE-2026-34486 — Apache Tomcat EncryptInterceptor RCE

> O módulo de comunicação de cluster **Apache Tomcat** Tribes falha ao descartar mensagens quando a descriptografia do `EncryptInterceptor` falha, permitindo que atacantes não autenticados acionem **Execução Remota de Código** via desserialização Java na porta 4000.

![Apache Tomcat](https://img.shields.io/badge/Apache%20Tomcat-9.0.0.M1--9.0.116-red?logo=apachetomcat) ![CVE](https://img.shields.io/badge/CVE-2026--34486-critical?color=critical) ![CVSS](https://img.shields.io/badge/CVSS-7.5-orange) ![Python](https://img.shields.io/badge/Python-3.6+-blue?logo=python) ![Java](https://img.shields.io/badge/Java-11+-orange?logo=openjdk) ![Docker](https://img.shields.io/badge/Docker-ready-blue?logo=docker) ![License](https://img.shields.io/badge/License-MIT-green)

* * *

## Detalhes da Vulnerabilidade