{"id":"CVE-2026-68569","title":"Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g","summary":"Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tom…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-287","CWE-305"],"vendor":"apache","product":"tomcat","affected":["tomcat >= 7.0.0, <= 7.0.109","tomcat >= 8.5.0, < 9.0.121","tomcat >= 10.1.0, < 10.1.58","tomcat >= 11.0.0, < 11.0.25"],"patched":["tomcat 11.0.25"],"published":"2026-08-25","updated":"2026-09-21","sourceUpdated":"2026-09-21T12:17:17.257","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68569","references":[{"url":"https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zc","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/26/8","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-68569.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-68569"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524160"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68569"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68569"},{"url":"https://access.redhat.com/errata/RHSA-2026:68257"},{"url":"https://access.redhat.com/errata/RHSA-2026:68258"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00525,"epssPercentile":0.43317,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-26T18:38:39.170628Z"},"ingestedAt":"2026-09-21T11:35:54.437Z","scores":{"nvd":8.1,"vendor":8.2},"slug":"CVE-2026-68569","body":"## Overview\n\nImproper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\n\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.\n\n## Affected\n\n- `tomcat >= 7.0.0, <= 7.0.109`\n- `tomcat >= 8.5.0, < 9.0.121`\n- `tomcat >= 10.1.0, < 10.1.58`\n- `tomcat >= 11.0.0, < 11.0.25`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tomcat 11.0.25`\n\n## Vendor advisories\n\n- **RHSA-2026:68257** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68257)\n- **RHSA-2026:68258** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68258)\n- **Red Hat VEX** · Important · affected: Red Hat JBoss Web Server 5, Red Hat JBoss Web Server 6, Red Hat JBoss Web Server 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, … · no fix planned: Red Hat JBoss Web Server 5, Red Hat JBoss Web Server 6, Red Hat JBoss Web Server 7 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-68569.json)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}