Apache Tomcat: authentication bypass
Critical9.8CVE-2026-76183 · Published Sep 23, 2026 · updated Sep 30, 2026
Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache Tomcat Product | >= 11.0.0-M1, <= 11.0.25 | No fix yet |
| >= 10.1.0-M1, <= 10.1.59 | No fix yet | |
| >= 9.0.0.M1, <= 9.0.121 | No fix yet | |
| >= 8.5.0, <= 8.5.100 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-289
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat | Medium6.5 | No fix yet |
| Sep 23 | Apache Tomcat: race condition | High8.1 | No fix yet |
| Sep 23 | Apache Sling XSS: cross-site scripting | Medium6.1 | 2.4.12 |
| Sep 23 | Apache Sling XSS: cross-site scripting | Medium6.1 | 2.4.12 |
| Sep 23 | Apache Sling XSS: cross-site scripting | Medium6.1 | 2.4.12 |
| Sep 23 | Apache Sling XSS: cross-site scripting | Medium6.1 | 2.4.12 |