AUGUST 28, 2026
Live Feed
Back to database
Case File

CVE-2026-68525

CRITICAL · CVSS 9.1 EPSS 0.55%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache Tomcat's FORM authentication process is vulnerable to an incorrect authorization flaw that allows attackers to bypass security constraints, enabling unauthorized access to resources via POST requests while restricting GET requests. This affects multiple versions, including those that are end-of-life, making it critical for organizations still using these versions to prioritize upgrades to 11.0.25, 10.1.58, or 9.0.121 to mitigate potential security risks. Users of affected versions should act promptly to ensure their systems are secure against this vulnerability.

CVE
CVE-2026-68525
Severity
CRITICAL
CVSS
9.1
EPSS
0.55%
Apache

Original NVD Description

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)