CVE-2026-34486
KEVHIGH 7.5EPSS 98.6%
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 98.62% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-08-04
- Nuclei
- critical · CWE-502
- Published
- 2026-04-09
- Updated
- 2026-08-10
Proof-of-concept exploits (7)
- 404-src/CVE-2026-344869★ · 2026-04-15
- AirSkye/CVE-2026-34486-poc12★ · 2026-04-15
- punitdarji/tomcat-cve-2026-344861★ · 2026-04-15
- striga-ai/CVE-2026-3448670★ · 2026-05-11
- anonmrc/CVE-2026-34486-e-Tomcat-Tribes0★ · 2026-05-19
- razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction0★ · 2026-07-23
- CypherHippie/CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization0★ · 2026-08-19