CVE-2026-86248: pre-auth authentication bypass in Apache Software Foundation Apache Tomcat

An unauthenticated network attacker can bypass CLIENT_CERT authentication in Apache Tomcat, allowing access control to fail unexpectedly (CVE-2026-86248). Affects Tomcat 11.x releases 11.0.0-M14 through 11.0.25, 10.x releases 10.1.22 through 10.1.59, and 9.x releases 9.0.92 through 9.0.121. The issue occurs in scenarios involving CLIENT_CERT processing when soft-fail is disabled and requires only network access to a vulnerable Tomcat instance; no user interaction or credentials are needed.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00386
CWE
CWE-287
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high priority for internet-facing Tomcat servers because the flaw can be triggered without credentials; if you expose CLIENT_CERT-protected endpoints, immediately restrict access and follow vendor guidance.

What is CVE-2026-86248?

An unauthenticated network attacker can bypass CLIENT_CERT authentication in Apache Tomcat, allowing access control to fail unexpectedly (CVE-2026-86248). Affects Tomcat 11.x releases 11.0.0-M14 through 11.0.25, 10.x releases 10.1.22 through 10.1.59, and 9.x releases 9.0.92 through 9.0.121. The issue occurs in scenarios involving CLIENT_CERT processing when soft-fail is disabled and requires only network access to a vulnerable Tomcat instance; no user interaction or credentials are needed. The weakness is classified as CWE-287 (Improper Authentication).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apache Software Foundation Apache Tomcat are affected?

BRANCHAFFECTEDFIXED
11.x11.0.0-M14 – 11.0.25
10.x10.1.22 – 10.1.59
9.x9.0.92 – 9.0.121

Is CVE-2026-86248 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-86248

  1. Restrict network exposure to Tomcat management and CLIENT_CERT-protected endpoints (use firewall or network ACLs).
  2. Enable heightened logging and monitor authentication and TLS client certificate failures for anomalies.
  3. Follow the Apache Tomcat advisory and apply vendor guidance as soon as vendor-supplied fixes or mitigations are released.
  4. Temporarily adjust or remove reliance on CLIENT_CERT authentication where feasible until a vendor fix is applied.

Frequently asked questions

Is CVE-2026-86248 being actively exploited?

There are no public reports of exploitation of CVE-2026-86248 as of 2026-09-30.

Which Apache Tomcat versions are affected by CVE-2026-86248?

Apache Tomcat releases affected are 11.x from 11.0.0-M14 through 11.0.25, 10.x from 10.1.22 through 10.1.59, and 9.x from 9.0.92 through 9.0.121.

Is there a patch for CVE-2026-86248?

No vendor-supplied fix is listed in the provided facts; follow Apache Tomcat guidance and plan to apply an official patch when it is published.

Does CVE-2026-86248 require authentication?

No, the vulnerability can be triggered without authentication; it affects CLIENT_CERT processing and can be reached over the network without credentials.

References