What is CVE-2026-34486?
A missing encryption of sensitive data vulnerability (CVE-2026-34486) has been discovered in Apache Tomcat that allows bypassing the EncryptInterceptor. This flaw can be chained with CVE-2025-24813 for exploitation and has been added to the KEV list. Affected Apache Tomcat users should apply security patches immediately.
Azərbaycanca: Apache Tomcat-də həssas məlumatların şifrələnməməsi zəifliyi (CVE-2026-34486) aşkar edilib ki, bu da EncryptInterceptor-in bypass edilməsinə imkan verir. Bu boşluq CVE-2025-24813 ilə zəncirlənərək istismar edilə bilər və KEV siyahısına daxil edilib. Təsirə məruz qalan Apache Tomcat istifadəçiləri dərhal təhlükəsizlik yamalarını tətbiq etməlidirlər.
Related CVEs
link basis: shared vendors: Claude, GPT, Tenable
FAQ2
Which component in Apache Tomcat does CVE-2026-34486 allow to be bypassed?
This vulnerability allows bypassing the EncryptInterceptor.
Which other vulnerability can CVE-2026-34486 be chained with for exploitation?
This flaw can be chained with CVE-2025-24813 for exploitation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.