Vulnerability
Published 2026-08-04
Verified 2026-09-19
Apache Tomcat (CVE-2026-34486)
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability. Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.
- Product
- Apache Tomcat
- Exploited in Australia?
- unknown
Primary: NVD · Vendor: CISA KEV · CVE: CVE-2026-34486
