Description
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
Published: 2026-04-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass
Action: Patch Immediately
AI Analysis

Impact

A flaw exists in Apache Tomcat’s handling of OCSP checks when the Forwarding Failure Mode (FFM) is used and soft-fail is disabled. In certain scenarios the client certificate authentication process does not fail as expected, allowing an attacker to present a valid or invalid certificate and still be granted authenticated access. The primary effect is an unauthorized elevation of privileges or the ability to impersonate a trusted client, thereby compromising the confidentiality and integrity of protected resources. The weakness underlying this issue is improper authentication, which is cataloged as CWE-287.

Affected Systems

Apache Tomcat versions 11.0.0-M14 through 11.0.20, 10.1.22 through 10.1.53, and 9.0.92 through 9.0.116 are impacted. Users running any of these releases should consider them vulnerable until the fix is applied.

Risk and Exploitability

The vulnerability provides an authentication bypass that can be exploited over the network, as interaction with the server requires no privileged user permissions. The exact CVSS score is not supplied in the available data, and EPSS information is lacking, but the nature of the flaw—unauthorized authentication—suggests a high potential for exploitation. The issue is not currently listed in the CISA Known Exploited Vulnerabilities catalog, indicating that publicly known exploits may not yet exist, yet the use case for an attacker to forge certificates remains feasible. The attack vector is likely external network traffic directed at the Tomcat service, and the attacker must generate or obtain a certificate that passes the server’s validation, though the server’s filters may inadvertently accept compromised certificates due to the bug.

Generated by OpenCVE AI on April 9, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Tomcat to version 11.0.21, 10.1.54, or 9.0.117, which contain the fix for this authentication issue.

Generated by OpenCVE AI on April 9, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-24j9-x2wg-9qv6 Apache Tomcat: CLIENT_CERT authentication does not fail as expected
History

Fri, 10 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Fri, 10 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-303
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Fri, 10 Apr 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache tomcat
Vendors & Products Apache
Apache tomcat

Fri, 10 Apr 2026 00:30:00 +0000

Type Values Removed Values Added
References

Thu, 09 Apr 2026 20:00:00 +0000

Type Values Removed Values Added
Description CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.
Title Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-04-10T14:22:31.310Z

Reserved: 2026-03-30T08:34:56.185Z

Link: CVE-2026-34500

cve-icon Vulnrichment

Updated: 2026-04-09T23:15:55.928Z

cve-icon NVD

Status : Received

Published: 2026-04-09T20:16:25.330

Modified: 2026-04-10T15:16:24.280

Link: CVE-2026-34500

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-09T19:36:52Z

Links: CVE-2026-34500 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T09:29:30Z

Weaknesses