Description
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.

Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.
Published: 2026-06-29
Score: 7.3 High
EPSS: 2.9% Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing critical step in authentication for Apache Tomcat when the JNDIRealm component is configured to perform GSSAPI authenticated binds. This deficiency allows an attacker to authenticate to the application without providing a valid password. The flaw is classified as a credential verification weakness (CWE-304). The impact is the ability to authenticate as any user without authorization.

Affected Systems

Apache Tomcat versions that are affected include the full range of releases from 7.0.0 through 7.0.109, 8.5.0 through 8.5.100, 9.0.0.M1 through 9.0.100, 10.1.0-M1 through 10.1.36, and 11.0.0-M1 through 11.0.4. The flaw is present in all major Tomcat branches up to the specified patch releases.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity, but the EPSS score is 3%, implying that the probability of exploitation is low. The flaw is not listed in the CISA KEV catalog, so no known public exploits are documented. No specific attack vector or environment requirements are stated in the CVE description beyond the need for JNDIRealm with GSSAPI, so the exploitation scenario remains unknown beyond that configuration.

Generated by OpenCVE AI on September 26, 2026 at 06:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the patched releases: 11.0.5, 10.1.37, or 9.0.101, which remove the flaw.
  • If an immediate upgrade cannot be performed, disable or remove the JNDIRealm configuration that enables GSSAPI authenticated bind.
  • If the JNDIRealm feature is not required, remove or disable it entirely.

Generated by OpenCVE AI on September 26, 2026 at 06:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache tomcat
Apache Tomcat
Apache Tomcat apache Tomcat
Vendors & Products Apache
Apache tomcat
Apache Tomcat
Apache Tomcat apache Tomcat

Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.
Title Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
Weaknesses CWE-304
References

Subscriptions

Apache Tomcat
Apache Tomcat Apache Tomcat
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-06-30T13:27:37.064Z

Reserved: 2026-06-17T19:25:28.759Z

Link: CVE-2026-55957

cve-icon Vulnrichment

Updated: 2026-06-30T13:27:27.008Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-29T21:16:45.700

Modified: 2026-07-02T19:01:45.887

Link: CVE-2026-55957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T06:15:06Z

Weaknesses
  • CWE-304

    Missing Critical Step in Authentication