Junglewise Threat Intelligence

CVE-2026-76183: Apache Tomcat authentication bypass in WebSocket endpoints

CVE-2026-76183 · Severity: critical · CVSS 9.8 · Published 2026-09-23

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is a Java-based application server used to run web applications and services. A security constraint bypass vulnerability in WebSocket endpoints allows attackers to access protected resources without proper authentication, potentially exposing sensitive data or enabling unauthorized actions on affected systems.

Technical details

An authentication bypass vulnerability in Apache Tomcat's WebSocket endpoint handling allows attackers to bypass security constraints through alternate name manipulation. The vulnerability affects multiple versions across major release lines and requires network access to WebSocket endpoints. A fix is available in versions 11.0.26, 10.1.60, and 9.0.122.

Affected products

  • Apache Tomcat 11.0.0-M1 through 11.0.25
  • Apache Tomcat 10.1.0-M1 through 10.1.59
  • Apache Tomcat 9.0.0-M1 through 9.0.121
  • Apache Tomcat 8.5.0 through 8.5.100
  • Apache Tomcat 7.0.43 through 7.0.109

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Fixed in Tomcat 11.0.26, 10.1.60, and 9.0.122

References

Related threats