CVE-2026-34500
published 2026-04-09CVE-2026-34500: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache…
PriorityP344medium6.5CVSS 3.1
AVNACHPRNUINSUCHILAN
EPSS
0.47%
38.0th percentile
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.22 < 10.1.54 | 10.1.54 |
| apache | tomcat | >= 11.0.1 < 11.0.21 | 11.0.21 |
| apache | tomcat | >= 9.0.92 < 9.0.117 | 9.0.117 |
| apache_software_foundation | apache_tomcat | 10.1.22 – 10.1.53 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M14 – 11.0.20 | — |
| apache_software_foundation | apache_tomcat | 9.0.92 – 9.0.116 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Tomcat up to 9.0.116/10.1.53/11.0.20 CLIENT_CERT Authentication improper authentication
vuldb·2026-04-09·CVSS 6.5
CVE-2026-34500 [MEDIUM] Apache Tomcat up to 9.0.116/10.1.53/11.0.20 CLIENT_CERT Authentication improper authentication
A vulnerability classified as critical was found in Apache Tomcat up to 9.0.116/10.1.53/11.0.20. This vulnerability affects unknown code of the component CLIENT_CERT Authentication. Such manipulation leads to improper authentication.
This vulnerability is listed as CVE-2026-34500. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
GHSA
GHSA-24j9-x2wg-9qv6: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat
ghsa_unreviewed·2026-04-09
CVE-2026-34500 GHSA-24j9-x2wg-9qv6: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
GHSA
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
ghsa·2026-04-09
CVE-2026-34500 [MEDIUM] CWE-287 Apache Tomcat: CLIENT_CERT authentication does not fail as expected
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
Red Hat
Apache Tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration
vendor_redhat·2026-04-09·CVSS 6.5
CVE-2026-34500 [MEDIUM] CWE-303 Apache Tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration
Apache Tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration
A flaw was found in Apache Tomcat. This vulnerability allows an attacker to bypass client certificate authentication in specific scenarios when the 'soft fail' option is disabled and the Flexible Failure Mechanism (FFM) is active. This could result in unauthorized access to sensitive resources that are intended to be protected by client certificates.
Statement: This Moderate impact flaw in Apache Tomcat allows for client certificate authentication bypass. This occurs when 'soft fail' is disabled and the Flexible Failure Mechanism (FFM) is active, potentially granting unauthorized access to resources protected by client certificates. Red Hat Enterprise Linux versions 6, 7, 8, 9, and 10, as well as
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34500 tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration [fedora-all]
bugzilla·2026-04-10·CVSS 6.5
CVE-2026-34500 [MEDIUM] CVE-2026-34500 tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration [fedora-all]
CVE-2026-34500 tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34500 Apache Tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration
bugzilla·2026-04-09·CVSS 6.5
CVE-2026-34500 [MEDIUM] CVE-2026-34500 Apache Tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration
CVE-2026-34500 Apache Tomcat: Apache Tomcat: Authentication bypass via client certificate misconfiguration
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
2026-04-09
Published