9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
CVE-2026-43515 — Apache Tomcat Security Constraint Bypass Exploitability verdict: confirmed exploitable. A POST request to a resource protected by a split configuration bypasses authentication entirely. The required web.xml shape is uncommon in...
Basic Information
ID
703A79DC-60E9-5AC8-928B-96E9607FCF0C
Published
Jun 19, 2026 at 11:08
Modified
Jun 19, 2026 at 16:02