SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-65183

HIGH · CVSS 8.1 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Apache Tomcat versions 11.0.0-M1 to 11.0.24, 10.1.0-M1 to 10.1.57, and 9.0.42 to 9.0.120 are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition that permits unauthorized local users to access the Unix domain socket. This vulnerability could lead to unauthorized data access or manipulation, posing a significant risk to system integrity. Organizations using the affected versions should prioritize upgrading to versions 11.0.25, 10.1.58, or 9.0.121 to mitigate this risk.

CVE
CVE-2026-65183
Severity
HIGH
CVSS
8.1
EPSS
0.45%
Apache

Original NVD Description

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)