CVE-2026-55955
published 2026-06-29CVE-2026-55955: Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects…
PriorityP341medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.28%
19.9th percentile
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | < 9.0.119 | 9.0.119 |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.56 | 10.1.56 |
| apache | tomcat | >= 11.0.0 < 11.0.23 | 11.0.23 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.55 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.22 | — |
| apache_software_foundation | apache_tomcat | 7.0.100 – 7.0.109 | — |
| apache_software_foundation | apache_tomcat | 8.5.38 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.13 – 9.0.118 | — |
| debian | tomcat9 | — | — |
| pki-deps_10.6 | pki-servlet-engine | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Tomcat up to 11.0.22 EncryptionInterceptor improper authentication (EUVD-2026-40231)
vuldb·2026-06-30
CVE-2026-55955 [CRITICAL] Apache Tomcat up to 11.0.22 EncryptionInterceptor improper authentication (EUVD-2026-40231)
A vulnerability was found in Apache Tomcat up to 7.0.109/8.5.100/9.0.118/10.1.55/11.0.22. It has been classified as critical. This affects an unknown function of the component EncryptionInterceptor. This manipulation causes improper authentication.
This vulnerability is handled as CVE-2026-55955. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
ghsa_unreviewed·2026-06-29
CVE-2026-55955 [MEDIUM] CWE-287 Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
Red Hat
tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor
vendor_redhat·2026-06-29·CVSS 4.2
CVE-2026-55955 [MEDIUM] CWE-294 tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor
tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor
A flaw was found in Apache Tomcat. An improper authentication vulnerability in the EncryptionInterceptor component allows a remote attacker to perform a replay attack. This could lead to unauthorized access or manipulation of data within the cluster component.
Statement: A flaw was found in Apache Tomcat's EncryptionInterceptor used for Tribes cluster communication. An improper authentication vulnerability allows a replay attack against encrypted cluster messages. Exploitation requires the EncryptionInterceptor to be configured for Tomcat clustering, which is a non-default configuration, and the attacker must have access to the cluster network to capture and replay messages. Apache rates this vulner
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55955 tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor
bugzilla·2026-06-29
CVE-2026-55955 [MEDIUM] CVE-2026-55955 tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor
CVE-2026-55955 tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
Bugzilla
CVE-2026-55955 tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor [fedora-all]
bugzilla·2026-06-29
CVE-2026-55955 [MEDIUM] CVE-2026-55955 tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor [fedora-all]
CVE-2026-55955 tomcat: Apache Tomcat: Replay attack via improper authentication in EncryptionInterceptor [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
2026-06-29
Published