cbcvebase.
CVE-2026-55276
published 2026-06-29

CVE-2026-55276: Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when…

PriorityP263critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.56%
44.7th percentile
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.

Affected

13 ranges
VendorProductVersion rangeFixed in
apachetomcat< 9.0.1199.0.119
apachetomcat
apachetomcat>= 10.1.0 < 10.1.5610.1.56
apachetomcat>= 11.0.0 < 11.0.2311.0.23
apache_software_foundationapache_tomcat10.1.0-M1 – 10.1.55
apache_software_foundationapache_tomcat11.0.0-M1 – 11.0.22
apache_software_foundationapache_tomcat8.5.0 – 8.5.100
apache_software_foundationapache_tomcat9.0.0.M1 – 9.0.118
debiantomcat10
debiantomcat11
debiantomcat9
pki-deps_10.6pki-servlet-engine
ubuntutomcat8

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2026-55276 is a logging-only flaw in Apache Tomcat where special roles and empty authorization constraints are omitted from the effective web.xml debug log output. Detection should focus on identifying vulnerable Tomcat versions in the environment (11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.0.M1 through 9.0.118, 8.5.0 through 8.5.100) and auditing whether administrators are relying solely on the effective web.xml debug log to verify security constraints.
  • When reviewing Tomcat debug logs for effective web.xml output, be aware that on affected versions the logged output may be incomplete — missing special roles and empty authorization constraints — which could cause administrators to misinterpret the actual security posture.
  • ·This is a logging-only issue with no runtime security impact. The flaw only affects the accuracy of debug log output for administrators reviewing the effective web.xml configuration — it does not affect actual runtime enforcement of authorization constraints.
  • ·Administrators should not rely solely on the effective web.xml debug log output to verify security constraint configuration on affected Tomcat versions.
  • ·Affected version ranges: Apache Tomcat 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.0.M1 through 9.0.118, and 8.5.0 through 8.5.100. Other end-of-support versions may also be affected. Fixed in 11.0.23, 10.1.56, and 9.0.119.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_ubuntu9.1CRITICAL
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.