
Apache Tomcat: Digest authenticator will authenticate any unknown user CVE: CVE-2026-43512 PT ID: PT-2026-40071 Vendor: Apache Software Foundation Product: Apache Tomcat CVSS: 9.8 Credits: n/a Description: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions may also be affected. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-43512 • https://lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73 PoC/Exploit: https://github.com/covepseng/cve-2026-43512-poc #dbugs_vuln
Post summary
Apache Tomcat digest authenticator flaw permits any unknown user to authenticate; a PoC exploit is available on GitHub, but no active exploitation is reported. The vulnerability has a CVSS score of 9.8.






