CVE-2026-34487
published 2026-04-09CVE-2026-34487: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.45%
36.2th percentile
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.54 | 10.1.54 |
| apache | tomcat | >= 11.0.0 < 11.0.21 | 11.0.21 |
| apache | tomcat | >= 9.0.13 < 9.0.117 | 9.0.117 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.53 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.20 | — |
| apache_software_foundation | apache_tomcat | 9.0.13 – 9.0.116 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files
vendor_redhat·2026-04-09·CVSS 7.5
CVE-2026-34487 [HIGH] CWE-538 Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files
Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files
A flaw was found in Apache Tomcat. The cloud membership for clustering component was vulnerable to the insertion of sensitive information into log files. This vulnerability could lead to the exposure of the Kubernetes bearer token, which is a credential used for authentication within a Kubernetes cluster, potentially allowing unauthorized access to cluster resources.
Statement: Low impact. This vulnerability in Apache Tomcat affects the cloud membership for clustering component, potentially exposing Kubernetes bearer tokens in log files. Exploitation requires the cloud membership feature to be enabled and an attacker to have access to the system's log files. Red Hat Enterprise Linux versions are affected
GHSA
GHSA-x4m4-345f-5h5g: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernete
ghsa_unreviewed·2026-04-09
CVE-2026-34487 CWE-532 GHSA-x4m4-345f-5h5g: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernete
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
GHSA
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
ghsa·2026-04-09
CVE-2026-34487 [HIGH] CWE-532 Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
VulDB
Apache Tomcat up to 9.0.116/10.1.53/11.0.20 Bearer Token log file
vuldb·2026-04-09·CVSS 7.5
CVE-2026-34487 [HIGH] Apache Tomcat up to 9.0.116/10.1.53/11.0.20 Bearer Token log file
A vulnerability classified as problematic has been found in Apache Tomcat up to 9.0.116/10.1.53/11.0.20. This affects an unknown part of the component Bearer Token Handler. This manipulation causes sensitive information in log files.
This vulnerability is tracked as CVE-2026-34487. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34487 tomcat: Apache Tomcat: Information disclosure via sensitive data in log files [fedora-all]
bugzilla·2026-04-10·CVSS 7.5
CVE-2026-34487 [HIGH] CVE-2026-34487 tomcat: Apache Tomcat: Information disclosure via sensitive data in log files [fedora-all]
CVE-2026-34487 tomcat: Apache Tomcat: Information disclosure via sensitive data in log files [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34487 Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files
bugzilla·2026-04-09·CVSS 7.5
CVE-2026-34487 [HIGH] CVE-2026-34487 Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files
CVE-2026-34487 Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
2026-04-09
Published