DIRAS TAKE
Treat this as high priority for internet-facing Tomcat servers because the flaw can be triggered without credentials; if you expose CLIENT_CERT-protected endpoints, immediately restrict access and follow vendor guidance.
What is CVE-2026-86248?
An unauthenticated network attacker can bypass CLIENT_CERT authentication in Apache Tomcat, allowing access control to fail unexpectedly (CVE-2026-86248). Affects Tomcat 11.x releases 11.0.0-M14 through 11.0.25, 10.x releases 10.1.22 through 10.1.59, and 9.x releases 9.0.92 through 9.0.121. The issue occurs in scenarios involving CLIENT_CERT processing when soft-fail is disabled and requires only network access to a vulnerable Tomcat instance; no user interaction or credentials are needed. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apache Software Foundation Apache Tomcat are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 11.x | 11.0.0-M14 – 11.0.25 | |
| 10.x | 10.1.22 – 10.1.59 | |
| 9.x | 9.0.92 – 9.0.121 |
Is CVE-2026-86248 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-86248
- Restrict network exposure to Tomcat management and CLIENT_CERT-protected endpoints (use firewall or network ACLs).
- Enable heightened logging and monitor authentication and TLS client certificate failures for anomalies.
- Follow the Apache Tomcat advisory and apply vendor guidance as soon as vendor-supplied fixes or mitigations are released.
- Temporarily adjust or remove reliance on CLIENT_CERT authentication where feasible until a vendor fix is applied.
Frequently asked questions
Is CVE-2026-86248 being actively exploited?
There are no public reports of exploitation of CVE-2026-86248 as of 2026-09-30.
Which Apache Tomcat versions are affected by CVE-2026-86248?
Apache Tomcat releases affected are 11.x from 11.0.0-M14 through 11.0.25, 10.x from 10.1.22 through 10.1.59, and 9.x from 9.0.92 through 9.0.121.
Is there a patch for CVE-2026-86248?
No vendor-supplied fix is listed in the provided facts; follow Apache Tomcat guidance and plan to apply an official patch when it is published.
Does CVE-2026-86248 require authentication?
No, the vulnerability can be triggered without authentication; it affects CLIENT_CERT processing and can be reached over the network without credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-86248
- cve.org/CVERecord?id=CVE-2026-86248
- lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk
- All Apache Software Foundation CVEs on CVE Radar
- CVEs published in September 2026