---
id: CVE-2026-55955
title: >-
  Improper Authentication vulnerability in Apache Tomcat allowed a replay attack
  against the EncryptionInterceptor in the cluster component.


  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from
  10.1.0-M1 through 10.1.55,…
summary: >-
  Improper Authentication vulnerability in Apache Tomcat allowed a replay attack
  against the EncryptionInterceptor in the cluster component.


  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from
  10.1.0-M1 through 10.1.55,…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-287
  - CWE-294
vendor: apache
product: tomcat
affected:
  - tomcat < 9.0.19
  - 'tomcat >= 10.1.0, < 10.1.56'
  - 'tomcat >= 11.0.0, < 11.0.23'
patched:
  - tomcat 11.0.23
published: '2026-06-29'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55955'
references:
  - url: 'https://lists.apache.org/thread/g4p5sf45p3f9r011pwqs9r54yd64s106'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/29/24'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55955.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-55955'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2494678'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-55955'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55955'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67163'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68651'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68677'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68680'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68678'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68679'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68659'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68660'
  - url: 'https://access.redhat.com/errata/RHSA-2026:29203'
  - url: 'https://access.redhat.com/errata/RHSA-2026:32960'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.00436
epssPercentile: 0.35213
ingestedAt: '2026-07-03T13:02:28.104Z'
scores:
  nvd: 6.5
  vendor: 4.2
---

## Overview

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.

Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.

## Affected

- `tomcat < 9.0.19`
- `tomcat >= 10.1.0, < 10.1.56`
- `tomcat >= 11.0.0, < 11.0.23`

## Remediation

Upgrade past the affected range:

- `tomcat 11.0.23`

## Vendor advisories

- **RHSA-2026:67163** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67163)
- **RHSA-2026:68651** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:68651)
- **RHSA-2026:68677** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68677)
- **RHSA-2026:68680** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68680)
- **RHSA-2026:68678** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68678)
- **RHSA-2026:68679** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68679)
- **RHSA-2026:68659** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68659)
- **RHSA-2026:68660** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68660)
- **RHSA-2026:29203** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:29203)
- **RHSA-2026:32960** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:32960)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat JBoss Web Server 5 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55955.json)
