Junglewise Threat Intelligence

CVE-2026-34487: Apache Tomcat sensitive information disclosure in clustering component

CVE-2026-34487 · Severity: high · CVSS 7.5 · Published 2026-04-09

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is a widely used web server and application container. A vulnerability in its clustering component could cause sensitive Kubernetes security tokens to be written into system log files. If an unauthorized person gains access to these logs, they could use the tokens to compromise the underlying cloud infrastructure.

Technical details

A CWE-532 (Insertion of Sensitive Information into Log File) vulnerability exists in the Apache Tomcat 'cloud membership for clustering' component. The root cause is the improper handling of Kubernetes bearer tokens, which are inadvertently written to log files during clustering operations. An attacker with access to the log files could retrieve these tokens to gain unauthorized access to the Kubernetes API. The issue affects Tomcat versions 9.x, 10.x, and 11.x; users should upgrade to 9.0.117, 10.1.54, or 11.0.21 respectively.

Affected products

  • Apache Tomcat 9.0.13 to 9.0.116, 10.1.0-M1 to 10.1.53, 11.0.0-M1 to 11.0.20
  • Apache Tomcat Tribes 9.0.13 to 9.0.116, 10.1.0-M1 to 10.1.53, 11.0.0-M1 to 11.0.20

Timeline

  • 2026-04-09: disclosed
  • 2026-04-09: advisory
  • 2026-04-09: patched

References

Related threats