{"schema_version":"1.9.0","id":"BIT-tomcat-2026-34486","published":"2026-04-13T05:53:08.595Z","modified":"2026-09-08T08:48:21.071862432Z","aliases":["CVE-2026-34486","GHSA-69r9-qgr7-g2wj"],"summary":"Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor","details":"Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\n\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\n\nUsers are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.","affected":[{"package":{"name":"tomcat","ecosystem":"Bitnami","purl":"pkg:bitnami/tomcat"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.0.116"},{"fixed":"9.0.117"},{"introduced":"10.1.53"},{"fixed":"10.1.54"},{"introduced":"11.0.20"},{"fixed":"11.0.21"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2026-34486.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}],"references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34486"},{"type":"ADVISORY","url":"https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat"},{"type":"ADVISORY","url":"https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-34486"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2457027"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36787"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36788"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36789"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36790"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36876"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36877"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36878"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36879"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37136"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37137"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:38505"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39188"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:39189"},{"type":"ADVISORY","url":"https://socradar.io/blog/snowlight-government-chinese-campaign/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486"}],"database_specific":{"cpes":["cpe:2.3:a:apache:tomcat:*:*:*:*:*:maven:*:*"],"severity":"High"}}