CVE-2026-68569
published 2026-08-25CVE-2026-68569: Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if…
PriorityP357high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.53%
42.9th percentile
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.58 | 10.1.58 |
| apache | tomcat | >= 11.0.0 < 11.0.25 | 11.0.25 |
| apache | tomcat | 7.0.0 – 7.0.109 | — |
| apache | tomcat | >= 8.5.0 < 9.0.121 | 9.0.121 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.57 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.24 | — |
| apache_software_foundation | apache_tomcat | 7.0.0 – 70.109 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.120 | — |
| debian | tomcat10 | — | — |
| debian | tomcat11 | — | — |
| debian | tomcat9 | — | — |
| pki-deps_10.6 | pki-servlet-engine | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g.
ghsa_unreviewed·2026-08-26
CVE-2026-68569 CWE-287 Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g.
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
VulDB
Apache Tomcat up to 7.0.109 DataSourceRealm improper authentication (EUVD-2026-66135 / Nessus ID 340128)
vuldb·2026-08-26·CVSS 8.1
CVE-2026-68569 [HIGH] Apache Tomcat up to 7.0.109 DataSourceRealm improper authentication (EUVD-2026-66135 / Nessus ID 340128)
A vulnerability was found in Apache Tomcat up to 11.0.24/10.1.57/9.0.120/8.5.100/7.0.109. It has been rated as critical. Impacted is an unknown function of the component DataSourceRealm. Performing a manipulation results in improper authentication.
This vulnerability is reported as CVE-2026-68569. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
Red Hat
tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure
vendor_redhat·2026-08-25·CVSS 8.1
CVE-2026-68569 [HIGH] CWE-305 tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure
tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
A flaw was found in Apache Tomcat. This improper authentication vulnerability allows a remot
No detection rules found.
No public exploits indexed.
2026-08-25
Published