CVE-2026-86248 Overview
Apache Tomcat contains an authentication bypass vulnerability in its CLIENT_CERT authentication mechanism [CWE-287]. When soft fail is disabled, authentication does not fail as expected in certain scenarios. Attackers can exploit this weakness over the network without prior credentials or user interaction. The flaw affects Apache Tomcat versions 11.0.0-M14 through 11.0.25, 10.1.22 through 10.1.59, and 9.0.92 through 9.0.121. The Apache Software Foundation has released fixed versions 11.0.26, 10.1.60, and 9.0.122.
Critical Impact
Unauthenticated network attackers can bypass client certificate authentication and gain unauthorized access to protected Tomcat resources, compromising confidentiality, integrity, and availability.
Affected Products
- Apache Tomcat 11.0.0-M14 through 11.0.25
- Apache Tomcat 10.1.22 through 10.1.59
- Apache Tomcat 9.0.92 through 9.0.121
Discovery Timeline
- 2026-09-23 - CVE-2026-86248 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-86248
Vulnerability Analysis
The vulnerability affects Apache Tomcat's CLIENT_CERT authentication path, a mechanism that validates client X.509 certificates during Transport Layer Security (TLS) handshakes. Administrators disable soft fail to enforce strict certificate validation, ensuring that requests without valid client certificates are rejected. This vulnerability breaks that expectation. Under specific conditions, requests that should trigger authentication failure are instead processed as authenticated. The issue is classified as Improper Authentication [CWE-287].
Exploitation requires no privileges, no user interaction, and can be performed remotely. Successful exploitation allows attackers to reach resources protected by certificate-based authentication constraints in web.xml. This undermines the security guarantee that mutual TLS provides for administrative consoles, internal APIs, and other sensitive endpoints.
Root Cause
The root cause is a logic flaw in how Tomcat evaluates CLIENT_CERT authentication outcomes when soft fail is disabled. Rather than terminating unauthenticated requests, the affected code paths permit request processing to continue in specific scenarios. Details are tracked in the Apache Tomcat security thread.
Attack Vector
The attack vector is network-based and requires no authentication. An attacker sends crafted HTTPS requests to a Tomcat instance configured with CLIENT_CERT authentication and soft fail disabled. When the vulnerable code path executes, the request bypasses certificate enforcement and reaches protected application resources. No verified public exploit or proof-of-concept has been published at this time.
No verified exploit code is publicly available. Refer to the Apache Tomcat announcement thread for maintainer discussion.
Detection Methods for CVE-2026-86248
Indicators of Compromise
- Successful access to endpoints protected by <auth-method>CLIENT_CERT</auth-method> from clients that did not present a valid X.509 certificate.
- Access log entries showing HTTP 200 responses on certificate-protected paths where the TLS handshake did not include client authentication.
- Session establishment in Tomcat Manager or Host Manager applications without corresponding certificate validation events.
Detection Strategies
- Correlate Tomcat access logs with TLS handshake logs to identify authenticated sessions lacking a client certificate exchange.
- Inspect running Tomcat instances for versions in the vulnerable ranges 11.0.0-M14 to 11.0.25, 10.1.22 to 10.1.59, and 9.0.92 to 9.0.121.
- Review server.xml connector configurations for clientAuth="true" combined with vulnerable Tomcat builds.
Monitoring Recommendations
- Enable verbose logging on org.apache.catalina.authenticator and org.apache.tomcat.util.net.SSLUtilBase to capture authentication decisions.
- Alert on authentication events targeting CLIENT_CERT protected contexts that lack an associated certificate subject.
- Track anomalous access patterns to administrative URIs previously protected by mutual TLS.
How to Mitigate CVE-2026-86248
Immediate Actions Required
- Upgrade Apache Tomcat to 11.0.26, 10.1.60, or 9.0.122 depending on your deployed branch.
- Inventory all Tomcat instances and identify those using CLIENT_CERT authentication with soft fail disabled.
- Rotate any secrets or session tokens that may have been issued during the exposure window.
Patch Information
The Apache Tomcat project has released patched versions that correct the CLIENT_CERT authentication logic. Users on the 11.x branch should upgrade to 11.0.26. Users on the 10.1.x branch should upgrade to 10.1.60. Users on the 9.0.x branch should upgrade to 9.0.122. Patch details are documented in the Apache Tomcat security announcement.
Workarounds
- Place a reverse proxy such as Apache HTTPD or NGINX in front of Tomcat to enforce client certificate validation independently.
- Restrict network access to certificate-protected endpoints using firewall rules or mutual TLS termination at a load balancer.
- Disable CLIENT_CERT authentication temporarily and require alternate authentication methods until patching is complete.
# Verify installed Tomcat version
$CATALINA_HOME/bin/version.sh
# Example: enforce client certificate validation at NGINX reverse proxy
# nginx.conf snippet
server {
listen 443 ssl;
ssl_client_certificate /etc/nginx/ca.crt;
ssl_verify_client on;
location / {
proxy_pass http://tomcat_backend;
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
