Executive brief
Apache Tomcat is an application server that runs web applications. When Jakarta Authentication is configured with SimpleAuthConfigProvider, the authentication realm of the first web application is incorrectly reused for all other web applications on the same server. An attacker could exploit this to access other users' accounts or data across different applications without proper authentication.
Technical details
The vulnerability is an improper authentication issue in Apache Tomcat's Jakarta Authentication implementation with SimpleAuthConfigProvider configured as the default provider. When multiple web applications use this provider, the authentication realm from the first application to process a request is reused for all subsequent authentication attempts across different applications, bypassing application-specific authentication contexts. This allows cross-context authentication bypass in multi-application deployments.
Affected products
- Apache Tomcat 8.5.0 through 8.5.100, 9.0.0.M4 through 9.0.121, 10.1.0-M1 through 10.1.59, 11.0.0-M1 through 11.0.25
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in versions 11.0.26, 10.1.60, 9.0.122