---
id: CVE-2026-34486
title: "Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the\_fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\n\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\n\nUsers are recommended to …"
summary: "Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the\_fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\n\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\n\nUsers are recommended to …"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-311
  - CWE-807
vendor: apache
product: tomcat
affected:
  - tomcat = 9.0.116
  - tomcat = 10.1.53
  - tomcat = 11.0.20
  - jboss_web_server = 7.0.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
  - enterprise_linux_els = 7.0
  - enterprise_linux_eus = 10.0
  - enterprise_linux_tus = 8.8
  - enterprise_linux_update_services_for_sap_solutions = 8.8
  - enterprise_linux_update_services_for_sap_solutions = 9.2
  - enterprise_linux_update_services_for_sap_solutions = 9.4
  - enterprise_linux_update_services_for_sap_solutions = 9.6
published: '2026-04-09'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:04.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34486'
references:
  - url: 'https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly'
    label: security@apache.org
  - url: >-
      https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:36787'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36788'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36789'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36790'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36876'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36877'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36878'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36879'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37136'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37137'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:38505'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:39188'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:39189'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-34486'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2457027'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://socradar.io/blog/snowlight-government-chinese-campaign/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-07T03:55:21.600269Z'
epss: 0.06561
epssPercentile: 0.93564
kev: true
kevDateAdded: '2026-08-04'
kevDueDate: '2026-08-07'
kevRansomware: false
exploits:
  github: 6
  githubRepos:
    - 'https://github.com/striga-ai/CVE-2026-34486'
    - 'https://github.com/AirSkye/CVE-2026-34486-poc'
    - 'https://github.com/404-src/CVE-2026-34486'
  nuclei:
    - CVE-2026-34486
  checkedAt: '2026-09-25T08:20:55.453Z'
ingestedAt: '2026-07-06T17:44:51.137Z'
---

## Overview

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

## Affected

- `tomcat = 9.0.116`
- `tomcat = 10.1.53`
- `tomcat = 11.0.20`
- `jboss_web_server = 7.0.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`
- `enterprise_linux_els = 7.0`
- `enterprise_linux_eus = 10.0`
- `enterprise_linux_tus = 8.8`
- `enterprise_linux_update_services_for_sap_solutions = 8.8`
- `enterprise_linux_update_services_for_sap_solutions = 9.2`
- `enterprise_linux_update_services_for_sap_solutions = 9.4`
- `enterprise_linux_update_services_for_sap_solutions = 9.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
