CVE-2026-34487Disclosure(apache / tomcat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache tomcat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-13: 104-0904-1004-13
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-091
Disclosure1
2026-04-101
Disclosure1
2026-04-131
Patch1
Full discourse3 posts
  • Kazuki Omo@omokazuki
    Disclosure

    SIOSセキュリティブログを更新しました。 Apache Tomcatの脆弱性(Important: CVE-2026-34486, Moderate: CVE-2026-34500, CVE-2026-32990, Low: CVE-2026-34487, CVE-2026-34483) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260410/

    Post summary

    A SIOS blog update announces several Apache Tomcat CVEs with severity ratings, but provides no proof of concept, exploit code, or mitigation guidance.

    00010165
    361 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Apache Tomcat` is affected by CVE-2026-34487, a high-severity flaw allowing sensitive info to be logged. Review configurations and apply vendor guidance when available. #ApacheTomcat #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-34487-apache-tomcat-log-file-insertion

    Post summary

    Apache Tomcat is vulnerable to CVE-2026-34487, a high‑severity flaw that can cause sensitive data to be logged. Administrators should review configurations and follow vendor guidance to mitigate the issue.

    0000045
    13 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34487 Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. … https://www.cve.org/CVERecord?id=CVE-2026-34487

    Post summary

    The statement announces CVE-2026-34487, detailing that a sensitive Kubernetes bearer token is unintentionally logged by the Apache Tomcat clustering component.

    0000089
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more