{"id":"CVE-2026-34486","title":"Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\n\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\n\nUsers are recommended to …","summary":"Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\n\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\n\nUsers are recommended to …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-311","CWE-807"],"vendor":"apache","product":"tomcat","affected":["tomcat = 9.0.116","tomcat = 10.1.53","tomcat = 11.0.20","jboss_web_server = 7.0.0","enterprise_linux = 8.0","enterprise_linux = 9.0","enterprise_linux = 10.0","enterprise_linux_els = 7.0","enterprise_linux_eus = 10.0","enterprise_linux_tus = 8.8","enterprise_linux_update_services_for_sap_solutions = 8.8","enterprise_linux_update_services_for_sap_solutions = 9.2","enterprise_linux_update_services_for_sap_solutions = 9.4","enterprise_linux_update_services_for_sap_solutions = 9.6"],"published":"2026-04-09","updated":"2026-09-21","sourceUpdated":"2026-09-21T19:17:04.670","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-34486","references":[{"url":"https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly","label":"security@apache.org"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2026:36787","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36788","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36789","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36790","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36876","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36877","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36878","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36879","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:37136","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:37137","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:38505","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:39188","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:39189","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-34486","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2457027","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://socradar.io/blog/snowlight-government-chinese-campaign/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","in-the-wild","exploit-available","kev"],"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"partial","timestamp":"2026-08-07T03:55:21.600269Z"},"epss":0.98616,"epssPercentile":0.99922,"kev":true,"kevDateAdded":"2026-08-04","kevDueDate":"2026-08-07","kevRansomware":false,"exploits":{"github":6,"githubRepos":["https://github.com/striga-ai/CVE-2026-34486","https://github.com/AirSkye/CVE-2026-34486-poc","https://github.com/404-src/CVE-2026-34486"],"nuclei":["CVE-2026-34486"],"checkedAt":"2026-09-23T07:14:01.190Z"},"ingestedAt":"2026-07-06T17:44:51.137Z","slug":"CVE-2026-34486","body":"## Overview\n\nMissing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\n\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\n\nUsers are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.\n\n## Affected\n\n- `tomcat = 9.0.116`\n- `tomcat = 10.1.53`\n- `tomcat = 11.0.20`\n- `jboss_web_server = 7.0.0`\n- `enterprise_linux = 8.0`\n- `enterprise_linux = 9.0`\n- `enterprise_linux = 10.0`\n- `enterprise_linux_els = 7.0`\n- `enterprise_linux_eus = 10.0`\n- `enterprise_linux_tus = 8.8`\n- `enterprise_linux_update_services_for_sap_solutions = 8.8`\n- `enterprise_linux_update_services_for_sap_solutions = 9.2`\n- `enterprise_linux_update_services_for_sap_solutions = 9.4`\n- `enterprise_linux_update_services_for_sap_solutions = 9.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":86,"depthScoreParts":{"impact":41.3,"likelihood":19.7,"exploitation":25,"ransomware":0},"changes":[{"seq":5130,"id":"CVE-2026-34486","ts":1788887249338,"field":"exploit_available","old":"false","new":"true"},{"seq":4013,"id":"CVE-2026-34486","ts":1788886365052,"field":"exploit_available","old":"true","new":"false"},{"seq":2825,"id":"CVE-2026-34486","ts":1788883031756,"field":"exploit_available","old":"false","new":"true"},{"seq":1854,"id":"CVE-2026-34486","ts":1788882434650,"field":"exploit_available","old":"true","new":"false"},{"seq":952,"id":"CVE-2026-34486","ts":1788881868686,"field":"exploit_available","old":"false","new":"true"},{"seq":173,"id":"CVE-2026-34486","ts":1787603621272,"field":"epss","old":"0.82933","new":"0.98616"},{"seq":116,"id":"CVE-2026-34486","ts":1785958647912,"field":"epss","old":"0.42627","new":"0.8116"},{"seq":112,"id":"CVE-2026-34486","ts":1785872093932,"field":"exploited","old":"false","new":"true"},{"seq":111,"id":"CVE-2026-34486","ts":1785872093932,"field":"kev","old":"false","new":"true"},{"seq":87,"id":"CVE-2026-34486","ts":1784920474250,"field":"epss","old":"0.21691","new":"0.42627"},{"seq":62,"id":"CVE-2026-34486","ts":1783709599794,"field":"epss","old":"0.15831","new":"0.21691"}]}