{"id":"CVE-2026-55276","title":"Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.\n\nThis issue affects Apache Tomcat: from 11.…","summary":"Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.\n\nThis issue affects Apache Tomcat: from 11.…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-670","CWE-778"],"vendor":"apache","product":"tomcat","affected":["tomcat < 9.0.119","tomcat >= 10.1.0, < 10.1.56","tomcat >= 11.0.0, < 11.0.23"],"patched":["tomcat 11.0.23"],"published":"2026-06-29","updated":"2026-07-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55276","references":[{"url":"https://lists.apache.org/thread/jy09xjlzn6r2qwvqoph8vcmf959yq68v","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/06/29/23","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55276.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-55276"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2494675"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-55276"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55276"},{"url":"https://access.redhat.com/errata/RHSA-2026:49951"},{"url":"https://access.redhat.com/errata/RHSA-2026:29203"},{"url":"https://access.redhat.com/errata/RHSA-2026:32960"}],"tags":["nvd","csaf","vex","red-hat","score-dispute"],"epss":0.00564,"epssPercentile":0.45646,"ingestedAt":"2026-07-03T13:02:28.102Z","scores":{"nvd":9.1,"vendor":2.3},"slug":"CVE-2026-55276","body":"## Overview\n\nAlways-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.\n\n## Affected\n\n- `tomcat < 9.0.119`\n- `tomcat >= 10.1.0, < 10.1.56`\n- `tomcat >= 11.0.0, < 11.0.23`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tomcat 11.0.23`\n\n## Vendor advisories\n\n- **RHSA-2026:49951** · Red Hat · fixed in: Red Hat JBoss Web Server 7.0 on RHEL 10, Red Hat JBoss Web Server 7.0 on RHEL 8, Red Hat JBoss Web Server 7.0 on RHEL 9 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:49951)\n- **RHSA-2026:29203** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:29203)\n- **RHSA-2026:32960** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:32960)\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat JBoss Web Server 5, … · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55276.json)","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}