AUGUST 28, 2026
Live Feed
Back to database
Case File

CVE-2026-68569

HIGH · CVSS 8.1 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.0.M1 through 9.0.120 are vulnerable due to an improper authentication flaw that allows users to be authenticated without existing in the DataSourceRealm, particularly in scenarios involving CLIENT-CERT and SPNEGO. This vulnerability could lead to unauthorized access, making it critical for organizations using affected versions to prioritize upgrading to 11.0.25, 10.1.58, or 9.0.121 to mitigate potential security risks. Users of older, unsupported versions (8.5.x and 7.0.x) should also take immediate action to address this vulnerability.

CVE
CVE-2026-68569
Severity
HIGH
CVSS
8.1
EPSS
0.45%
Apache

Original NVD Description

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)