• PATCH AVAILABLE

CVE-2026-76183: authentication bypass in Apache Software Foundation Apache Tomcat

Remote attackers can bypass authentication controls on Apache Tomcat WebSocket endpoints, allowing access to protected resources and operations; this is tracked as CVE-2026-76183. A wide range of Tomcat releases are affected: 11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, 9.0.0.M1 through 9.0.121, 8.5.0 through 8.5.100, and 7.0.43 through 7.0.109. Exploitation requires only network access to a vulnerable Tomcat instance hosting WebSocket endpoints; no credentials or user interaction are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.0039
CWE
CWE-289
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a pre-auth bypass affecting many common Tomcat releases, so prioritize mitigation — the bug lets unauthenticated network attackers reach protected WebSocket endpoints. Reduce internet exposure and apply vendor updates or guidance immediately.

What is CVE-2026-76183?

Remote attackers can bypass authentication controls on Apache Tomcat WebSocket endpoints, allowing access to protected resources and operations; this is tracked as CVE-2026-76183. A wide range of Tomcat releases are affected: 11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, 9.0.0.M1 through 9.0.121, 8.5.0 through 8.5.100, and 7.0.43 through 7.0.109. Exploitation requires only network access to a vulnerable Tomcat instance hosting WebSocket endpoints; no credentials or user interaction are required.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apache Software Foundation Apache Tomcat are affected?

BRANCHAFFECTEDFIXED
11.x11.0.0-M1 – 11.0.25
10.x10.1.0-M1 – 10.1.59
9.x9.0.0.M1 – 9.0.121
8.x8.5.0 – 8.5.100
7.x7.0.43 – 7.0.109
7.xbefore 7.0.437.0.43

Is CVE-2026-76183 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-76183

  1. Apply the vendor's Tomcat updates or follow the vendor's mitigation guidance for this CVE
  2. Restrict network exposure to Tomcat WebSocket endpoints (block or firewall access from untrusted networks)
  3. Enable and review access and WebSocket logs for unexpected connections or bypass attempts
  4. Harden application access controls and monitor for anomalies until vendor fixes are confirmed applied

Frequently asked questions

Is CVE-2026-76183 being actively exploited?

There are no public reports of exploitation as of 2026-09-30.

Which Apache Tomcat versions are affected by CVE-2026-76183?

Affected Tomcat releases include 11.0.0-M1–11.0.25, 10.1.0-M1–10.1.59, 9.0.0.M1–9.0.121, 8.5.0–8.5.100, and 7.0.43–7.0.109.

Is there a patch for CVE-2026-76183?

The vendor has made fixes available; follow Apache Tomcat's update guidance and apply the provided patches or updates as soon as possible.

Does CVE-2026-76183 require authentication?

No — the issue is an authentication bypass for WebSocket endpoints, allowing unauthenticated network access to protected endpoints.

References