DIRAS TAKE
Urgent: this is a pre-auth bypass affecting many common Tomcat releases, so prioritize mitigation — the bug lets unauthenticated network attackers reach protected WebSocket endpoints. Reduce internet exposure and apply vendor updates or guidance immediately.
What is CVE-2026-76183?
Remote attackers can bypass authentication controls on Apache Tomcat WebSocket endpoints, allowing access to protected resources and operations; this is tracked as CVE-2026-76183. A wide range of Tomcat releases are affected: 11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, 9.0.0.M1 through 9.0.121, 8.5.0 through 8.5.100, and 7.0.43 through 7.0.109. Exploitation requires only network access to a vulnerable Tomcat instance hosting WebSocket endpoints; no credentials or user interaction are required.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apache Software Foundation Apache Tomcat are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 11.x | 11.0.0-M1 – 11.0.25 | |
| 10.x | 10.1.0-M1 – 10.1.59 | |
| 9.x | 9.0.0.M1 – 9.0.121 | |
| 8.x | 8.5.0 – 8.5.100 | |
| 7.x | 7.0.43 – 7.0.109 | |
| 7.x | before 7.0.43 | 7.0.43 |
Is CVE-2026-76183 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-76183
- Apply the vendor's Tomcat updates or follow the vendor's mitigation guidance for this CVE
- Restrict network exposure to Tomcat WebSocket endpoints (block or firewall access from untrusted networks)
- Enable and review access and WebSocket logs for unexpected connections or bypass attempts
- Harden application access controls and monitor for anomalies until vendor fixes are confirmed applied
Frequently asked questions
Is CVE-2026-76183 being actively exploited?
There are no public reports of exploitation as of 2026-09-30.
Which Apache Tomcat versions are affected by CVE-2026-76183?
Affected Tomcat releases include 11.0.0-M1–11.0.25, 10.1.0-M1–10.1.59, 9.0.0.M1–9.0.121, 8.5.0–8.5.100, and 7.0.43–7.0.109.
Is there a patch for CVE-2026-76183?
The vendor has made fixes available; follow Apache Tomcat's update guidance and apply the provided patches or updates as soon as possible.
Does CVE-2026-76183 require authentication?
No — the issue is an authentication bypass for WebSocket endpoints, allowing unauthenticated network access to protected endpoints.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76183
- cve.org/CVERecord?id=CVE-2026-76183
- lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp
- All Apache Software Foundation CVEs on CVE Radar
- CVEs published in September 2026