GITHUBEXPLOIT 7.5 HIGH

Exploit for Missing Encryption of Sensitive Data in Apache Tomcat_842CCA4A-BD4C-5FC6-B699-7C1C4593B59D

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

CVE-2026-34486 EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization. Affected: 11.0.19+, 10.1.53+, 9.0.116+. Fixed in: 11.0.21, 10.1.54, 9.0.117. Found and reported by Bartlomiej...
Visit Original Source

Basic Information

ID 842CCA4A-BD4C-5FC6-B699-7C1C4593B59D
Published May 11, 2026 at 14:07
Modified May 11, 2026 at 14:14

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.