Skip to main content
Vulnerability Database/CVE-2026-75973

CVE-2026-75973: Apache Tomcat Auth Bypass Vulnerability

CVE-2026-75973 is an authentication bypass flaw in Apache Tomcat affecting Jakarta Authentication configurations. Attackers can exploit realm confusion across web applications. This post covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2026-75973 Overview

CVE-2026-75973 is an improper authentication vulnerability [CWE-287] in Apache Tomcat. The flaw occurs when Jakarta Authentication is configured with SimpleAuthConfigProvider as the default provider across multiple web applications. Under this configuration, the realm from the first web application that authenticates a request is reused for all other web applications sharing the provider. Attackers can leverage this behavior to authenticate against one application and be granted access under a different application's realm.

Critical Impact

Cross-application authentication confusion allows a user authenticated in one web application to be treated as authenticated under another web application's realm, breaking tenant isolation.

Affected Products

  • Apache Tomcat 11.0.0-M1 through 11.0.25
  • Apache Tomcat 10.1.0-M1 through 10.1.59
  • Apache Tomcat 9.0.0.M4 through 9.0.121 (and EOL 8.5.0 through 8.5.100)

Discovery Timeline

  • 2026-09-23 - CVE CVE-2026-75973 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-75973

Vulnerability Analysis

Apache Tomcat implements Jakarta Authentication (JASPIC) to allow pluggable authentication modules. When administrators configure SimpleAuthConfigProvider as the default provider and deploy multiple web applications that use it, Tomcat caches realm state improperly. The realm associated with the first web application to authenticate a request becomes the effective realm for subsequent authentications across all applications sharing the provider.

This behavior collapses the boundary between application-specific security realms. A principal authenticated against one application's realm can be recognized by another application, bypassing the intended per-application user store. The issue affects environments hosting multiple tenants or applications with distinct authentication authorities on the same Tomcat instance.

The network-exploitable nature of the flaw means no local access or user interaction is required. Attackers who possess valid credentials in a low-privilege application can potentially interact with higher-privilege applications on the same server.

Root Cause

The root cause is shared state within SimpleAuthConfigProvider when serving multiple web applications. The provider does not correctly scope the realm reference to the requesting web application, resulting in the first-in-wins behavior described in the advisory.

Attack Vector

Exploitation requires an attacker to send an authentication request to a vulnerable Tomcat instance hosting multiple web applications that share SimpleAuthConfigProvider. Once authentication succeeds in the first application, subsequent authenticated requests to other applications resolve against the wrong realm. See the Apache Mailing List Thread and the OpenWall OSS Security Update for full technical context. No verified proof-of-concept code is publicly available at time of publication.

Detection Methods for CVE-2026-75973

Indicators of Compromise

  • Authenticated sessions in one web application accessing resources of another application without a distinct login event.
  • Access log entries showing authenticated principals that do not exist in the target application's user store.
  • Tomcat instances running affected versions with SimpleAuthConfigProvider declared as the default Jakarta Authentication provider.

Detection Strategies

  • Inventory Tomcat deployments and identify versions in the affected ranges (11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, 9.0.0.M4 through 9.0.121, and EOL 8.5.x).
  • Review META-INF/context.xml and server-level configuration for Jakarta Authentication providers referencing SimpleAuthConfigProvider.
  • Correlate authentication events across co-hosted applications to detect principals appearing in realms where they are not provisioned.

Monitoring Recommendations

  • Enable Tomcat access and authentication logging with per-application context to surface cross-realm principal usage.
  • Forward Tomcat and application authentication logs to a centralized analytics platform for correlation across web applications.
  • Alert on privileged operations performed by principals lacking an authoritative record in the target application's user directory.

How to Mitigate CVE-2026-75973

Immediate Actions Required

  • Upgrade Apache Tomcat to 11.0.26, 10.1.60, or 9.0.122 depending on your branch.
  • Migrate off end-of-life 8.5.x deployments, which remain affected and receive no fixes.
  • Audit all Tomcat instances hosting multiple web applications that use Jakarta Authentication.

Patch Information

The Apache Tomcat project has released fixed versions 11.0.26, 10.1.60, and 9.0.122. Users on the 8.5.x branch must upgrade to a supported branch, as 8.5 was EOL when the CVE was assigned. Full release details are available on the Apache Mailing List Thread.

Workarounds

  • Reconfigure Jakarta Authentication to avoid using SimpleAuthConfigProvider as the default provider across multiple web applications.
  • Isolate web applications requiring distinct realms onto separate Tomcat instances until the patch is applied.
  • Restrict network exposure of affected Tomcat servers to trusted clients until remediation is complete.
bash
# Verify installed Tomcat version and locate JASPIC configuration
$CATALINA_HOME/bin/version.sh
grep -R "SimpleAuthConfigProvider" $CATALINA_HOME/conf $CATALINA_BASE/webapps

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.