CVE-2026-65182
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Summary
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1 <= 11.0.24 | affected |
| Apache Software Foundation | Apache Tomcat | 10.1.0-M1 <= 10.1.57 | affected |
| Apache Software Foundation | Apache Tomcat | 9.0.0.M1 <= 9.0.120 | affected |
| Apache Software Foundation | Apache Tomcat | 8.5.0 <= 8.5.100 | affected |
| Apache Software Foundation | Apache Tomcat | 7.0.0 <= 7.0.109 | affected |
| Apache Software Foundation | Apache Tomcat | 0 < 7.0.0 | unknown |
Weaknesses
- CWE-284: CWE-284 Improper Access Control
- CWE-863: CWE-863 Incorrect Authorization
ADP Enrichment
CVE Program Container
Additional References
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.