Skip to main content
Vulnerability Database/CVE-2026-86248

CVE-2026-86248: Apache Tomcat Auth Bypass Vulnerability

CVE-2026-86248 is an authentication bypass flaw in Apache Tomcat affecting CLIENT_CERT authentication when soft fail is disabled. This security issue allows unauthorized access in certain scenarios. This post covers technical details, affected versions from 9.0.92 through 11.0.25, impact assessment, and mitigation strategies.

Published:

CVE-2026-86248 Overview

Apache Tomcat contains an authentication bypass vulnerability in its CLIENT_CERT authentication mechanism [CWE-287]. When soft fail is disabled, authentication does not fail as expected in certain scenarios. Attackers can exploit this weakness over the network without prior credentials or user interaction. The flaw affects Apache Tomcat versions 11.0.0-M14 through 11.0.25, 10.1.22 through 10.1.59, and 9.0.92 through 9.0.121. The Apache Software Foundation has released fixed versions 11.0.26, 10.1.60, and 9.0.122.

Critical Impact

Unauthenticated network attackers can bypass client certificate authentication and gain unauthorized access to protected Tomcat resources, compromising confidentiality, integrity, and availability.

Affected Products

  • Apache Tomcat 11.0.0-M14 through 11.0.25
  • Apache Tomcat 10.1.22 through 10.1.59
  • Apache Tomcat 9.0.92 through 9.0.121

Discovery Timeline

  • 2026-09-23 - CVE-2026-86248 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-86248

Vulnerability Analysis

The vulnerability affects Apache Tomcat's CLIENT_CERT authentication path, a mechanism that validates client X.509 certificates during Transport Layer Security (TLS) handshakes. Administrators disable soft fail to enforce strict certificate validation, ensuring that requests without valid client certificates are rejected. This vulnerability breaks that expectation. Under specific conditions, requests that should trigger authentication failure are instead processed as authenticated. The issue is classified as Improper Authentication [CWE-287].

Exploitation requires no privileges, no user interaction, and can be performed remotely. Successful exploitation allows attackers to reach resources protected by certificate-based authentication constraints in web.xml. This undermines the security guarantee that mutual TLS provides for administrative consoles, internal APIs, and other sensitive endpoints.

Root Cause

The root cause is a logic flaw in how Tomcat evaluates CLIENT_CERT authentication outcomes when soft fail is disabled. Rather than terminating unauthenticated requests, the affected code paths permit request processing to continue in specific scenarios. Details are tracked in the Apache Tomcat security thread.

Attack Vector

The attack vector is network-based and requires no authentication. An attacker sends crafted HTTPS requests to a Tomcat instance configured with CLIENT_CERT authentication and soft fail disabled. When the vulnerable code path executes, the request bypasses certificate enforcement and reaches protected application resources. No verified public exploit or proof-of-concept has been published at this time.

No verified exploit code is publicly available. Refer to the Apache Tomcat announcement thread for maintainer discussion.

Detection Methods for CVE-2026-86248

Indicators of Compromise

  • Successful access to endpoints protected by <auth-method>CLIENT_CERT</auth-method> from clients that did not present a valid X.509 certificate.
  • Access log entries showing HTTP 200 responses on certificate-protected paths where the TLS handshake did not include client authentication.
  • Session establishment in Tomcat Manager or Host Manager applications without corresponding certificate validation events.

Detection Strategies

  • Correlate Tomcat access logs with TLS handshake logs to identify authenticated sessions lacking a client certificate exchange.
  • Inspect running Tomcat instances for versions in the vulnerable ranges 11.0.0-M14 to 11.0.25, 10.1.22 to 10.1.59, and 9.0.92 to 9.0.121.
  • Review server.xml connector configurations for clientAuth="true" combined with vulnerable Tomcat builds.

Monitoring Recommendations

  • Enable verbose logging on org.apache.catalina.authenticator and org.apache.tomcat.util.net.SSLUtilBase to capture authentication decisions.
  • Alert on authentication events targeting CLIENT_CERT protected contexts that lack an associated certificate subject.
  • Track anomalous access patterns to administrative URIs previously protected by mutual TLS.

How to Mitigate CVE-2026-86248

Immediate Actions Required

  • Upgrade Apache Tomcat to 11.0.26, 10.1.60, or 9.0.122 depending on your deployed branch.
  • Inventory all Tomcat instances and identify those using CLIENT_CERT authentication with soft fail disabled.
  • Rotate any secrets or session tokens that may have been issued during the exposure window.

Patch Information

The Apache Tomcat project has released patched versions that correct the CLIENT_CERT authentication logic. Users on the 11.x branch should upgrade to 11.0.26. Users on the 10.1.x branch should upgrade to 10.1.60. Users on the 9.0.x branch should upgrade to 9.0.122. Patch details are documented in the Apache Tomcat security announcement.

Workarounds

  • Place a reverse proxy such as Apache HTTPD or NGINX in front of Tomcat to enforce client certificate validation independently.
  • Restrict network access to certificate-protected endpoints using firewall rules or mutual TLS termination at a load balancer.
  • Disable CLIENT_CERT authentication temporarily and require alternate authentication methods until patching is complete.
bash
# Verify installed Tomcat version
$CATALINA_HOME/bin/version.sh

# Example: enforce client certificate validation at NGINX reverse proxy
# nginx.conf snippet
server {
    listen 443 ssl;
    ssl_client_certificate /etc/nginx/ca.crt;
    ssl_verify_client on;
    location / {
        proxy_pass http://tomcat_backend;
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.