CVE-2026-59084 – Apache Tomcat
“Even strong security features fail when secure configuration isn't clearly defined.”
A patch is available for CVE-2026-59084, a vulnerability affecting Apache Tomcat. The issue stems from insufficient technical documentation for securely configuring the EncryptInterceptor, which could leave deployments vulnerable if the feature is not configured correctly. The vulnerability is associated with CWE-1059 (Insufficient Technical Documentation).
The issue affects Apache Tomcat 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.13 through 9.0.119, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109. Users should upgrade to Apache Tomcat 11.0.24, 10.1.57, or 9.0.120, which address the issue.
The CVSS score is 9.1, which is Critical severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.
Key Details
- Affected Product
- Apache Tomcat
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-1059