cbcvebase.
CVE-2026-29145
published 2026-04-09

CVE-2026-29145: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This…

PriorityP261critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.71%
49.6th percentile
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

Affected

13 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat>= 10.1.1 < 10.1.5310.1.53
apachetomcat>= 11.0.0 < 11.0.2011.0.20
apachetomcat>= 9.0.83 < 9.0.1169.0.116
apachetomcat_native>= 1.1.23 < 1.3.71.3.7
apachetomcat_native>= 2.0.0 < 2.0.142.0.14
apache_software_foundationapache_tomcat10.1.0-M7 – 10.1.52
apache_software_foundationapache_tomcat11.0.0-M1 – 11.0.18
apache_software_foundationapache_tomcat9.0.83 – 9.0.115
apache_software_foundationapache_tomcat_native1.1.23 – 1.1.34
apache_software_foundationapache_tomcat_native1.2.0 – 1.2.39
apache_software_foundationapache_tomcat_native1.3.0 – 1.3.6
apache_software_foundationapache_tomcat_native2.0.0 – 2.0.13

Detection & IOCsextracted from sources · hover to see the quote

  • Detect Apache Tomcat CLIENT_CERT authentication bypass attempts by monitoring for successful authentication to certificate-protected resources without a valid client certificate being presented, particularly when softFail is disabled in the Tomcat configuration.
  • Audit Apache Tomcat conf/server.xml for SSLHostConfig or Connector elements where clientAuth is not set to 'required' and softFail is not explicitly enabled — these configurations are the precondition for exploitation.
  • Flag access to resources protected by CLIENT_CERT authentication on affected Tomcat versions (9.0.83–9.0.115, 10.1.0-M7–10.1.52, 11.0.0-M1–11.0.18) where no client certificate was supplied in the TLS handshake but the request was not rejected.
  • ·Vulnerability is only exploitable when CLIENT_CERT authentication is configured AND 'soft fail' is explicitly disabled. Deployments not using CLIENT_CERT auth are not affected.
  • ·Affected Tomcat Native versions span three release branches: 1.1.23–1.1.34, 1.2.0–1.2.39, and 1.3.0–1.3.6, as well as 2.0.0–2.0.13. All must be checked when assessing the native connector layer.
  • ·Red Hat has deferred fixes across RHEL 7, 8, 9, 10 and JBoss Web Server 5 & 6 packages; patched upstream versions are Tomcat 9.0.116, 10.1.53, 11.0.20 and Tomcat Native 1.3.7 / 2.0.14.
  • ·A Tomcat service restart is required after any conf/server.xml configuration change for the mitigation to take effect.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.